detection-engineering
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed of documentation and workflow instructions. It does not contain executable code, command-line instructions, or network-enabled tools.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process threat behavior data and telemetry information, which constitutes an attack surface for indirect prompt injection. However, because the skill lacks the ability to execute code or perform network exfiltration, this surface poses no direct security risk to the environment.
- Ingestion points: External telemetry data sources (process, network, auth, etc.) and threat behavior descriptions (SKILL.md).
- Boundary markers: No explicit boundary markers or delimiters defined for processing external data.
- Capability inventory: File system writes to create rule files, tests, and documentation. No network or shell execution capabilities identified.
- Sanitization: The instructions do not define specific sanitization or filtering logic for the generated outputs.
Audit Metadata