splunk-identity-saml-readiness-advisor

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill follows best practices for a diagnostic tool, including robust boundary markers for untrusted documentation and strict limitations on shell command execution.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves information from official Splunk documentation and community domains (e.g., help.splunk.com, docs.splunk.com). These well-known sources are appropriate for the skill's purpose and do not represent a security risk.
  • [PROMPT_INJECTION]: The skill processes untrusted data via web searches (Ingestion points: Phase 2 documentation search). Boundary markers are present in the form of explicit instructions to ignore instructions in retrieved text. The skill has shell execution capabilities via the splsearch tool, but provides strict sanitization rules requiring output redaction and placeholder validation. These measures address the indirect prompt injection surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:30 PM
Security Audit — agent-trust-hub — splunk-identity-saml-readiness-advisor