detection-engineering-coverage-evaluation
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to fetch and process threat intelligence from external URLs, which introduces a potential surface for indirect prompt injection where malicious instructions could be embedded in source text.
- Ingestion Points: External content is retrieved via web fetching tools or raw text input in the first step of the workflow.
- Boundary Markers: The skill instructs the agent to clean HTML elements and UI boilerplate, which helps isolate core content but does not use specific delimiters for LLM interpolation.
- Capability Inventory: The agent utilizes tools to generate detection logic and has the capability to write to the SecOps environment via the
create_ruletool. - Sanitization: The workflow includes a dedicated verification step that scans extracted text for known injection patterns and requires explicit human approval before any generated rules are deployed to the environment.
Audit Metadata