ghidra
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: The skill serves as a high-quality instructional guide and script repository for the Ghidra reverse engineering framework, a legitimate open-source tool.
- [EXTERNAL_DOWNLOADS]: Mentions official download paths for Ghidra and several well-known community extensions (e.g., Mandiant's Ghidrathon, CERT Kaiju). These references are informational, targeting reputable organizations and well-known services within the cybersecurity community.
- [COMMAND_EXECUTION]: Documentation provides standard command-line examples for Ghidra's
analyzeHeadlessutility. This allows for automated batch processing of binaries, which is a core function of the software. - [DYNAMIC_EXECUTION]: The skill provides Python/Jython scripts designed to run within Ghidra's internal scripting environment. These scripts facilitate typical analysis tasks, such as cross-referencing suspicious API imports (e.g.,
VirtualAlloc,WriteProcessMemory) and extracting strings from analyzed programs. - [DATA_EXPOSURE]: Analysis scripts include functionality to write results to the local
/tmpdirectory. This is standard behavior for generating local analysis reports and does not involve unauthorized data transmission or network exfiltration.
Audit Metadata