volatility3
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the Volatility framework and associated symbol packs from the official Volatility Foundation GitHub repository. These are well-known resources within the security community.
- [COMMAND_EXECUTION]: Provides a library of commands for forensic triage, including process analysis, network connection scanning, and kernel module inspection.
- [DATA_EXPOSURE]: Includes instructions for dumping Windows registry hives (SAM, SYSTEM, SECURITY) and using third-party tools like Impacket's secretsdump to extract credential hashes. This is documented as a legitimate forensic capability for authorized investigations.
- [INDIRECT_PROMPT_INJECTION]: The skill processes memory images (untrusted external data) via the -f parameter. It defines specific capabilities for artifact extraction (procdump, dumpfiles) and establishes boundary markers through explicit plugin selection. Sanitization relies on the forensic analyst's manual review of the tool's output.
Audit Metadata