investigation-query
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- Indirect Prompt Injection: The skill is designed to ingest and analyze external investigation logs. While this creates a potential surface for instructions embedded within the log data, the skill includes procedural safeguards such as mandatory log entry citations and explicit gap-flagging protocols to ensure the agent remains grounded in the provided evidence.
- Modular Skill Reference: The instructions rely on a separate reference skill (
internal-investigation) to handle the substantive log-query logic. This modular design is a standard practice for organizing complex agent workflows and does not introduce unusual security risks. - Absence of Sensitive Operations: The skill does not request network access, file system modifications, or the execution of external scripts. It functions entirely through natural language instructions for data analysis and reporting.
Audit Metadata