microsoft-sentinel

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance for authoring KQL queries in Microsoft Sentinel. The instructions are strictly technical and aligned with cloud security monitoring best practices.
  • [SAFE]: All code snippets consist of standard KQL syntax for querying Log Analytics tables (e.g., SigninLogs, AuditLogs, AzureActivity). No commands for external network communication (e.g., curl, wget) or local system modification were found.
  • [SAFE]: The documentation includes a detailed anti-pattern reference (references/Anti-Patterns.md) that encourages security, performance, and accuracy in detection engineering.
  • [SAFE]: No obfuscation, prompt injection attempts, or unauthorized persistence mechanisms were identified. The skill adheres to the 'least privilege' and 'least surprise' principles by referencing local workspace schema documents for column names rather than making external calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:12 AM