skills/mukul975/anthropic-cybersecurity-skills/building-soc-playbook-for-ransomware/Gen Agent Trust Hub
building-soc-playbook-for-ransomware
Pass
Audited by Gen Agent Trust Hub on Mar 15, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXPOSURE]: The automation script
scripts/agent.pydisables SSL certificate verification when connecting to the Splunk management API usingverify=Falsein the requests call. This is a common best-practice violation that could allow for intercepting traffic in insecure network environments. - [CREDENTIALS_UNSAFE]: The script accepts sensitive security tokens, such as the CrowdStrike API token and Splunk session key, as command-line arguments. This can expose credentials to other users on the system via process listing tools or command history.
- [EXTERNAL_DOWNLOADS]: The IR automation script interacts with established external security services including
id-ransomware.malwarehunterteam.com,nomoreransom.org, andmb-api.abuse.chfor the purpose of ransomware identification and finding decryptors.
Audit Metadata