secops-triage

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Data Processing Considerations: The skill ingests external data such as alert details, case descriptions, and entity values through tools like get_case and udm_search. This represents a potential surface for indirect prompt injection if alert metadata contains malicious instructions.
  • Ingestion points: Processes data from ${ALERT_ID}, ${CASE_ID}, and SIEM search results in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the triage workflow.
  • Capability inventory: The skill utilizes case management capabilities including execute_bulk_close_case, create_case_comment, and update_case.
  • Sanitization: The instructions do not explicitly describe sanitization or validation of the ingested alert content.
  • Security Tool Integration: The skill interacts with specialized security operations tools (e.g., udm_search, summarize_entity, get_ioc_match). These tools are used within their intended scope for security monitoring and case management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:50 PM
Security Audit — agent-trust-hub — secops-triage