hunting-threats
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for utilizing
defuddle.md, a third-party markdown conversion service, to fetch external security documentation. This involves performing network requests to a domain that is not included in the standard whitelist of trusted services. - [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its mechanism for ingesting and processing untrusted data from the web.
- Ingestion points: External public advisories, specifications, and vendor reports fetched via the
defuddle.mdutility as described in SKILL.md. - Boundary markers: Absent; there are no instructions provided to use delimiters or explicit 'ignore instructions' warnings when processing the fetched content.
- Capability inventory: The skill facilitates the execution of complex telemetry queries and investigative actions within SIEM platforms including Splunk, KQL, and Elastic.
- Sanitization: The conversion process focus is on stripping HTML boilerplate for token efficiency; it does not include validation or sanitization of the resulting text to prevent embedded instructions from influencing the agent's logic.
Audit Metadata