analyzing-malware-persistence-with-autoruns

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The Python script provided in the SKILL.md file executes the 'autorunsc64.exe' system utility via the subprocess.run method to perform local persistence scans. This is a legitimate and necessary operation for the skill's primary purpose of security auditing and malware analysis.- [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or obfuscation were detected. The skill uses standard Windows system utilities and follows common security analysis workflows. Administrative privileges and system access mentioned in the prerequisites are consistent with the requirements of the Sysinternals Autoruns tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 06:44 PM