writing-sigma-rules

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing several Python packages from public registries, including sigma-cli and various pySigma backends (Splunk, Elasticsearch, Kusto, QRadar) to support rule conversion tasks.
  • [COMMAND_EXECUTION]: Instructions involve the use of local command-line utilities such as sigma, hayabusa, and chainsaw for checking rule schema and performing offline validation against event logs (EVTX files).
  • [EXTERNAL_DOWNLOADS]: The skill suggests using an external service (defuddle.md) via curl to fetch and convert online threat intelligence or advisories into Markdown format for easier processing.
  • [DATA_EXFILTRATION]: The skill includes an explicit operational security (OPSEC) warning regarding the use of external URL extraction services, advising against routing sensitive client infrastructure or live adversary indicators through third-party platforms.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing untrusted external data (threat advisories and vendor reports). While it provides instructions for the agent to ingest this data, the primary purpose is for the creation of structured YAML rules, and the skill includes guidance on verifying and testing the resulting logic to mitigate errors or malicious data influences.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — writing-sigma-rules