extracting-iocs-from-malware-samples

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill is a legitimate cybersecurity tool that automates the forensic extraction of indicators from malware samples without any hidden malicious functionality.- [EXTERNAL_DOWNLOADS]: Network activity is restricted to the VirusTotal API for indicator validation. This is a well-known service and the implementation correctly uses user-provided API keys.- [COMMAND_EXECUTION]: Shell commands are used appropriately for local file analysis, utilizing standard utilities like tshark and hashing tools for processing provided forensic data.- [PROMPT_INJECTION]: The skill's instructions are focused on analysis workflows and do not contain any patterns designed to bypass agent safety or override system instructions.- [DATA_EXFILTRATION]: No unauthorized data exfiltration was detected; network requests are confined to validating extracted data against trusted third-party threat intelligence databases.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 01:51 PM