secops-hunt
Pass
Audited by Gen Agent Trust Hub on Jun 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a template for security analysts to perform threat hunting. It utilizes standard security tools (e.g.,
udm_search,list_cases) that are expected in a SecOps context. - [SAFE]: The instruction references local configuration files (e.g.,
extensions/google-secops/TOOL_MAPPING.md) to map capabilities to available tools, which is a common pattern for platform-specific extensions. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as IOCs and MITRE TTP descriptions provided by the analyst or retrieved from external campaigns. While this is an ingestion surface, the risk is LOW as it is the primary purpose of a security hunting tool and the operations (SIEM searches) are scoped to data analysis rather than system execution.
- [DATA_EXFILTRATION]: The skill includes instructions to write files or post to SOAR. These are legitimate reporting and incident management actions within a security workflow and do not involve unauthorized exfiltration of sensitive system credentials or private data.
Audit Metadata