yara-rule-authoring
Pass
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: LOW
Full Analysis
- [SAFE] (SAFE): No malicious behavior or security risks identified. The skill content is purely educational and provides reference material for security researchers.
- [EXTERNAL_DOWNLOADS] (INFO): The 'scripts/pyproject.toml' file identifies 'yara-x' and 'ruff' as dependencies, which are trusted industry-standard tools for malware analysis and code linting.
- [COMMAND_EXECUTION] (INFO): Documentation references the use of 'uv run' to execute local utility scripts ('atom_analyzer.py', 'yara_lint.py'). While the script contents are not provided in the skill, their described use cases (linting and performance analysis) are consistent with legitimate detection engineering workflows.
Audit Metadata