siem-rules

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not contain any executable scripts, remote code downloads, or exfiltration patterns. While it processes user-provided content such as log samples and query drafts, it incorporates a comprehensive 'Prompt Injection Safety Notice' (Section 8) that specifically instructs the agent to treat embedded directives as data rather than commands. The prompt injection alert from static analysis is a false positive, as the triggering phrase 'ignore previous instructions' is used within documentation to explain how to defend against such attacks. The skill adheres to security best practices and maintains clear role boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:06 AM
Security Audit — agent-trust-hub — siem-rules