secops-hunt

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill is designed to process external data, including indicators of compromise (IOCs), campaign IDs, and threat actor details provided by the user. This data is subsequently used to construct search queries and generate markdown reports.
  • Ingestion points: User-provided values for ${GTI_COLLECTION_ID}, ${TECHNIQUE_IDS}, ${SEARCH_TERMS}, and manual IOC lists described in SKILL.md.
  • Boundary markers: The skill does not explicitly define delimiters or instructions to isolate user-provided inputs from the rest of the prompt logic when performing searches or generating reports.
  • Capability inventory: The skill utilizes tools for searching security data (udm_search, get_ioc_match, search_security_events), managing case data (list_cases, get_case), and writing reports to the file system (write_file).
  • Sanitization: No explicit sanitization or validation of the input strings is mentioned before they are interpolated into queries or final reports.
  • [Command Execution]: The skill facilitates the execution of specialized tools to interact with security operations platforms and the local environment.
  • The workflow involves using tools like udm_search and list_cases to retrieve telemetry and incident data. These tools are part of the intended SecOps functionality.
  • The write_file capability is used to generate report files based on hunt findings. These actions are aligned with the threat hunter persona's objectives.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:50 PM
Security Audit — agent-trust-hub — secops-hunt