investigation-query

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection: The skill is designed to ingest and analyze external investigation logs. While this creates a potential surface for instructions embedded within the log data, the skill includes procedural safeguards such as mandatory log entry citations and explicit gap-flagging protocols to ensure the agent remains grounded in the provided evidence.
  • Modular Skill Reference: The instructions rely on a separate reference skill (internal-investigation) to handle the substantive log-query logic. This modular design is a standard practice for organizing complex agent workflows and does not introduce unusual security risks.
  • Absence of Sensitive Operations: The skill does not request network access, file system modifications, or the execution of external scripts. It functions entirely through natural language instructions for data analysis and reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:01 PM
Security Audit — agent-trust-hub — investigation-query