yara
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides commands to clone YARA rules from established community and industry repositories, including sources from Mandiant and the Yara-Rules project.\n- [COMMAND_EXECUTION]: Documentation includes instructions for executing the YARA command-line utility for scanning files, directories, and memory dumps.\n- [PRIVILEGE_ESCALATION]: The skill notes that scanning process memory on Linux systems using the PID argument requires root privileges, which is standard functionality for memory forensics.
Audit Metadata