skills/aeondave/malskill/capa/Gen Agent Trust Hub

capa

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the capa binary from Mandiant's official releases on GitHub and clones rule definitions from the mandiant/capa-rules repository. It also references reputable security projects such as the CAPE sandbox (CAPEv2) and unipacker for binary analysis workflows.
  • [COMMAND_EXECUTION]: The instructions involve executing common shell utilities (wget, unzip, chmod, pip, capa, jq, grep) to manage tool installation and process analysis results. These commands are consistent with the documented purpose of binary triage.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data, specifically binary executables and sandbox-generated JSON reports.
  • Ingestion points: Ingests external JSON sandbox reports via the capa command line (documented in SKILL.md and references/capability-driven-triage.md).
  • Boundary markers: The instructions do not define specific delimiters or warnings for the agent to treat tool output as untrusted content.
  • Capability inventory: Workflows utilize subprocess execution of analysis tools and data processing via jq and grep.
  • Sanitization: There is no explicit sanitization step for the external report data before it is presented in the analysis context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — capa