microsoft-defender-endpoint

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance and templates for authoring KQL queries in Microsoft Defender for Endpoint. All provided code snippets are benign and represent standard threat hunting techniques.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or credential exposure was found. The instructions focus on proper query structure and optimization.
  • [SAFE]: The skill does not perform any external network operations or file system modifications. It references other internal skills (e.g., kusto-query-language) and vendor-specific products (OpenTide MDR) in a legitimate documentation context.
  • [SAFE]: Anti-patterns documentation provides helpful security analysis guidance for avoiding common errors in KQL authoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:12 AM