sleuth-kit
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for running legitimate forensics tools (mmls, fls, icat, etc.) on local disk images for analysis purposes.
- [PRIVILEGE_ESCALATION]: The skill uses sudo for standard administrative tasks like installing forensic packages via apt and mounting encrypted or forensic volumes.
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data from disk images, which is an inherent ingestion surface. While malicious data in an image could attempt to influence an agent, this is an expected condition in forensics. 1. Ingestion points: Forensic analysis of disk.img via TSK. 2. Boundary markers: None specified. 3. Capability inventory: Local tool execution and file extraction to the local filesystem. 4. Sanitization: None.
Audit Metadata