building-detection-rule-with-splunk-spl

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The Python utility scripts/agent.py uses the well-known requests library to communicate with the Splunk REST API for rule deployment. These network operations are necessary for the skill's primary functionality.
  • [COMMAND_EXECUTION]: The script scripts/agent.py performs file system operations to write generated detection reports in JSON format to the local system. The scripts/process.py file also generates configuration stanzas intended for savedsearches.conf.
  • [SAFE]: The skill implements a comprehensive validation engine in scripts/process.py that evaluates SPL queries for performance risks (such as excessive wildcard use) and logical errors before they are deployed.
  • [SAFE]: All external references in the documentation point to legitimate industry resources including official Splunk documentation and the MITRE ATT&CK framework.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 02:48 AM