performing-file-carving-with-foremost

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes external forensic utilities including foremost, scalpel, and file to process disk images and identify carved file types. All command executions in the Python script and workflow use the subprocess module with argument lists, which prevents shell injection vulnerabilities. The commands perform standard directory management and file identification tasks necessary for the forensic purpose.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install forensic tools from official system repositories using apt-get. External references point to well-known and reputable security projects including the Sleuth Kit and official Foremost documentation sites.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 12:22 AM