skills/mukul975/anthropic-cybersecurity-skills/conducting-social-engineering-pretext-call/Gen Agent Trust Hub
conducting-social-engineering-pretext-call
Pass
Audited by Gen Agent Trust Hub on Mar 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a structured toolkit for cybersecurity professionals to conduct social engineering assessments. It follows best practices by emphasizing the need for written authorization and legal compliance.
- [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety filters were found. The pretext templates (e.g., impersonating IT helpdesk) are data intended for the user's assessment and do not target the agent's internal logic.
- [REMOTE_CODE_EXECUTION]: The skill does not contain any remote code execution patterns. It mentions standard security tools like 'theHarvester' and libraries like 'twilio' and 'requests' for legitimate assessment and tracking purposes.
- [DATA_EXFILTRATION]: No unauthorized data access or network exfiltration patterns were detected. The Python scripts ('agent.py' and 'process.py') perform local file I/O for campaign management and reporting.
- [COMMAND_EXECUTION]: While the skill provides example command-line usage for 'theHarvester', these are instructional and do not involve the automated execution of arbitrary or dangerous system commands.
Audit Metadata