hunting-threats

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for utilizing defuddle.md, a third-party markdown conversion service, to fetch external security documentation. This involves performing network requests to a domain that is not included in the standard whitelist of trusted services.
  • [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its mechanism for ingesting and processing untrusted data from the web.
  • Ingestion points: External public advisories, specifications, and vendor reports fetched via the defuddle.md utility as described in SKILL.md.
  • Boundary markers: Absent; there are no instructions provided to use delimiters or explicit 'ignore instructions' warnings when processing the fetched content.
  • Capability inventory: The skill facilitates the execution of complex telemetry queries and investigative actions within SIEM platforms including Splunk, KQL, and Elastic.
  • Sanitization: The conversion process focus is on stripping HTML boilerplate for token efficiency; it does not include validation or sanitization of the resulting text to prevent embedded instructions from influencing the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — hunting-threats