siem-rules
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely educational and instructional, providing templates for KQL (Microsoft Sentinel) and SPL (Splunk) queries. It does not possess capabilities for network access, file modification, or command execution.
- [PROMPT_INJECTION]: While the skill contains keywords associated with prompt injection (e.g., 'ignore previous instructions'), these are utilized within a defensive 'Safety Notice' section. This section explicitly directs the agent to treat directives found within user-provided log samples or query drafts as data rather than commands, which is a recommended security practice to mitigate indirect prompt injection.
- [SAFE]: The skill uses a restricted set of read-only tools and follows the principle of least privilege, focusing entirely on producing production-ready query text for human review.
Audit Metadata