building-red-team-c2-infrastructure-with-havoc

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a configuration and management toolkit for the Havoc C2 framework. All included scripts and documentation are transparent and align with legitimate cybersecurity research and red teaming activities.
  • [COMMAND_EXECUTION]: Instructions in the documentation involve standard Linux package management and building software from source. These commands are necessary for the deployment of the framework and do not exhibit suspicious behavior.
  • [EXTERNAL_DOWNLOADS]: The skill clones the source code for the Havoc framework from its official GitHub repository. This is a standard and expected method for acquiring the software.
  • [CREDENTIALS_UNSAFE]: Example configuration files and templates use clear placeholders for passwords and tokens. No sensitive credentials or secrets are exposed within the skill files.
  • [DATA_EXFILTRATION]: The management scripts are designed to interact with a teamserver provided by the user via command-line arguments. There are no patterns suggesting the unauthorized collection or transmission of sensitive local data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 11:37 PM