soc-siem
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for a Security Operations Center (SOC) that ingests untrusted telemetry from various external sources, which constitutes an inherent attack surface for indirect prompt injection.\n
- Ingestion points: Telemetry is collected from Wazuh agents on VMs/containers, Suricata sensors monitoring network traffic, and cloud-native logs such as AWS CloudTrail and VPC flow logs (SKILL.md Step 2, references/stack-architecture.md).\n
- Boundary markers: The skill relies on technical normalization processes (decoders) rather than explicit delimiters to structure data for the agent's context (references/stack-architecture.md).\n
- Capability inventory: The system includes capabilities for host isolation, process termination, and network blocking via Wazuh active-response and Suricata IPS, though these are gated by approval workflows (references/operations.md).\n
- Sanitization: The architecture uses a 'Normalize' stage where Wazuh decoders parse raw telemetry into structured, normalized field sets before evaluation (references/stack-architecture.md).\n- [COMMAND_EXECUTION]: The skill references the execution of security validation tools and system-level mutations.\n
- Evidence: Instructions include using
wazuh-logtestandsuricata -Tto validate detection rules (SKILL.md Step 4).\n - Evidence: The skill describes operational responses such as host isolation and credential revocation, but strictly mandates that these must never be performed 'freehand' and instead require a reviewed change and explicit approval (SKILL.md Step 7, references/operations.md).
Audit Metadata