analyzing-network-traffic-for-incidents

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/agent.py uses subprocess.run to execute various network analysis tools including tshark, suricata, and tcpdump. These calls are parameterized and used as intended for the skill's primary purpose of network forensic analysis.
  • Evidence in scripts/agent.py functions: run_tshark, get_pcap_summary, detect_data_exfiltration, detect_ids_alerts, and extract_http_objects.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 06:44 PM