opensearch-detection-engineer

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a secure-by-default workflow, requiring explicit field validation through OpenSearch mapping APIs before any detection rules are created or modified.
  • [COMMAND_EXECUTION]: Utilizes local bash commands and inline Python scripts to parse JSON output from OpenSearch APIs. These commands are used for legitimate administrative tasks such as counting indices or checking alias mappings.
  • [DATA_EXFILTRATION]: All network operations (via OpenSearch APIs) are directed towards the user's configured OpenSearch cluster for detection management. No unauthorized data exfiltration patterns were detected.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or external script downloads were found. The skill relies entirely on local references and standard platform tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 10:18 AM
Security Audit — agent-trust-hub — opensearch-detection-engineer