secops-triage
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- Data Processing Considerations: The skill ingests external data such as alert details, case descriptions, and entity values through tools like
get_caseandudm_search. This represents a potential surface for indirect prompt injection if alert metadata contains malicious instructions. - Ingestion points: Processes data from
${ALERT_ID},${CASE_ID}, and SIEM search results inSKILL.md. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the triage workflow.
- Capability inventory: The skill utilizes case management capabilities including
execute_bulk_close_case,create_case_comment, andupdate_case. - Sanitization: The instructions do not explicitly describe sanitization or validation of the ingested alert content.
- Security Tool Integration: The skill interacts with specialized security operations tools (e.g.,
udm_search,summarize_entity,get_ioc_match). These tools are used within their intended scope for security monitoring and case management.
Audit Metadata