skills/mukul975/anthropic-cybersecurity-skills/analyzing-lnk-file-and-jump-list-artifacts/Gen Agent Trust Hub
analyzing-lnk-file-and-jump-list-artifacts
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate forensic analysis capabilities for Windows systems, including metadata extraction and timeline creation.
- [SAFE]: The included Python scripts (agent.py, process.py) implement safe binary parsing techniques using the struct module to handle the Shell Link Binary format.
- [SAFE]: The suspicious indicator detection logic in agent.py is designed to identify common cyber attack patterns (e.g., LOLBins, obfuscated PowerShell) in LNK files, which is consistent with its forensic purpose.
- [SAFE]: Dependencies and external tools mentioned (LECmd, JLECmd, LnkParse3) are well-recognized and trusted utilities in the digital forensics and incident response (DFIR) community.
Audit Metadata