writing-sigma-rules
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing several Python packages from public registries, including
sigma-cliand variouspySigmabackends (Splunk, Elasticsearch, Kusto, QRadar) to support rule conversion tasks. - [COMMAND_EXECUTION]: Instructions involve the use of local command-line utilities such as
sigma,hayabusa, andchainsawfor checking rule schema and performing offline validation against event logs (EVTX files). - [EXTERNAL_DOWNLOADS]: The skill suggests using an external service (
defuddle.md) viacurlto fetch and convert online threat intelligence or advisories into Markdown format for easier processing. - [DATA_EXFILTRATION]: The skill includes an explicit operational security (OPSEC) warning regarding the use of external URL extraction services, advising against routing sensitive client infrastructure or live adversary indicators through third-party platforms.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing untrusted external data (threat advisories and vendor reports). While it provides instructions for the agent to ingest this data, the primary purpose is for the creation of structured YAML rules, and the skill includes guidance on verifying and testing the resulting logic to mitigate errors or malicious data influences.
Audit Metadata