Skip to content

[Security AI Prompts] Update Entity Highlights prompt for empty-signal guardrails#20262

Open
tcalopes wants to merge 2 commits into
elastic:mainfrom
tcalopes:279617-entity-highlights-prompt-empty-signals
Open

[Security AI Prompts] Update Entity Highlights prompt for empty-signal guardrails#20262
tcalopes wants to merge 2 commits into
elastic:mainfrom
tcalopes:279617-entity-highlights-prompt-empty-signals

Conversation

@tcalopes

@tcalopes tcalopes commented Jul 21, 2026

Copy link
Copy Markdown

Update the entityDetailsHighlights prompt content to more strongly instruct the model to omit empty-signal filler / recommendations.

Proposed commit message

Update the entityDetailsHighlights Security AI prompt (aiForEntityDetails group) used by the Entity Analytics "Entity summary" flyout in the Security Solution.

WHAT:

  • Rewrites the prompt so highlights are only included when that signal is present and non-empty; recommended actions are omitted when there is nothing concrete to recommend; and filler such as "no anomalies detected" is discouraged.
  • Content-only change to the single entityDetailsHighlights saved object; the saved-object id, type, and filename are unchanged.
  • Bumps the package version 1.0.131.0.14 (patch, content-only) with a matching changelog.yml entry.

WHY:

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Author's Checklist

How to test this PR locally

  1. Build and serve the package (requires Docker running):
    cd packages/security_ai_prompts
    elastic-package lint
    elastic-package build
    elastic-package stack up -d -v --services package-registry

tcalopes and others added 2 commits July 21, 2026 11:55
…l guardrails

Mirror the Kibana entityDetailsHighlights prompt from elastic/kibana#279617 so the Security AI Prompts saved object matches the in-code fallback. Bump package version 1.0.13 -> 1.0.14.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@andrewkroh andrewkroh added the Integration:security_ai_prompts Security AI Prompts label Jul 21, 2026
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

@tcalopes
tcalopes marked this pull request as ready for review July 21, 2026 17:21
@tcalopes
tcalopes requested a review from a team as a code owner July 21, 2026 17:21
@CAWilson94

Copy link
Copy Markdown

@tcalopes please feel free to close #19999 if no longer relevant

@tcalopes

Copy link
Copy Markdown
Author

@tcalopes please feel free to close #19999 if no longer relevant

@CAWilson94 unfortunately I don't think I have permission to do that

@mergify

mergify Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

@CAWilson94

Copy link
Copy Markdown

@tcalopes all good, closed it off. Thanks for getting this over the line 🔥

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants