implementing-mitre-attack-coverage-mapping
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a legitimate guide for cybersecurity operations, specifically for identifying gaps in detection coverage using the MITRE ATT&CK framework.
- [SAFE]: The provided Splunk (SPL) and Azure Sentinel (KQL) queries are designed to export detection rule metadata for analysis; they do not contain commands for data exfiltration, deletion, or unauthorized access.
- [SAFE]: The external URLs referenced in the documentation belong to well-known and reputable cybersecurity organizations, such as MITRE, CyberDefenders, and Datadog.
- [SAFE]: No patterns of prompt injection, obfuscation, or unauthorized remote code execution were identified within the skill's instructions or scripts.
Audit Metadata