kusto-query-language

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent on how to process and decode untrusted data, such as Base64-encoded command lines from security logs. This establishes a surface for indirect prompt injection where malicious instructions could be embedded in the logs being analyzed by the agent.
  • Ingestion points: Security log tables (e.g., ProcessTable, NetworkTable, SigninLogs) containing data potentially controlled by attackers.
  • Boundary markers: The skill focuses on query logic and does not provide specific instructions for the agent to use delimiters or 'ignore embedded instructions' markers when interpreting analyzed strings.
  • Capability inventory: The skill is limited to KQL query generation; it does not grant the agent capabilities for local shell execution, file system writes, or network requests from its own execution environment.
  • Sanitization: The instructions recommend KQL-based extraction and normalization (e.g., parse_command_line, replace_string) rather than sanitization meant to prevent agent misinterpretation of data as instructions.
  • [SAFE]: The skill promotes optimization best practices, such as prioritizing indexed filters (Time, 'has', '==') and avoiding performance anti-patterns like full-column scans or inefficient string operators.
  • [SAFE]: External documentation references point to official Microsoft Azure and Defender resources, which are recognized as well-known and trusted services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:12 AM