siem-rules

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides KQL and SPL query templates for security engineering. No malicious code, unauthorized tool usage, or credential exposure was detected.- [PROMPT_INJECTION]: Static analysis flagged the string 'ignore previous instructions'. Contextual review confirms this is part of a safety notice (Section 8) instructing the agent to disregard adversarial commands if they appear within log samples or user-provided queries.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data such as SIEM logs (Ingestion point). It proactively addresses this risk through dedicated instructions in Section 8 (Boundary markers and Sanitization) and limits the agent to a minimal set of file-reading tools (Capability inventory: Read, Grep, Glob).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:11 PM
Security Audit — agent-trust-hub — siem-rules