microsoft-defender-endpoint
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured guidance and templates for authoring KQL queries in Microsoft Defender for Endpoint. All provided code snippets are benign and represent standard threat hunting techniques.
- [SAFE]: No evidence of prompt injection, data exfiltration, or credential exposure was found. The instructions focus on proper query structure and optimization.
- [SAFE]: The skill does not perform any external network operations or file system modifications. It references other internal skills (e.g., kusto-query-language) and vendor-specific products (OpenTide MDR) in a legitimate documentation context.
- [SAFE]: Anti-patterns documentation provides helpful security analysis guidance for avoiding common errors in KQL authoring.
Audit Metadata