hec-setup-and-troubleshooting
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong data protection policies, explicitly instructing the agent to never request or repeat HEC tokens or authorization headers, and to use placeholders like
$HEC_TOKENfor secrets. - [SAFE]: Explicit instructions for data sanitization are present throughout the workflow, requiring redaction of hostnames, ports, and other identifiers that could reveal customer environments in diagnostic evidence.
- [SAFE]: The skill correctly identifies the risk of indirect prompt injection from user-provided evidence (such as logs, HTTP responses, or search results) and explicitly directs the agent to treat such data as untrusted evidence and never as executable instructions.
- [SAFE]: All external URLs and references point to official Splunk documentation (
help.splunk.com), which is consistent with the skill's stated purpose and authorship.
Audit Metadata