detection-engineering-coverage-evaluation

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to fetch and process threat intelligence from external URLs, which introduces a potential surface for indirect prompt injection where malicious instructions could be embedded in source text.
  • Ingestion Points: External content is retrieved via web fetching tools or raw text input in the first step of the workflow.
  • Boundary Markers: The skill instructs the agent to clean HTML elements and UI boilerplate, which helps isolate core content but does not use specific delimiters for LLM interpolation.
  • Capability Inventory: The agent utilizes tools to generate detection logic and has the capability to write to the SecOps environment via the create_rule tool.
  • Sanitization: The workflow includes a dedicated verification step that scans extracted text for known injection patterns and requires explicit human approval before any generated rules are deployed to the environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:52 PM
Security Audit — agent-trust-hub — detection-engineering-coverage-evaluation