skills/aeondave/malskill/zeek/Gen Agent Trust Hub

zeek

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains comprehensive shell-based workflows for processing network logs. This includes the use of utilities like cat, grep, awk, and jq to extract and correlate data from protocol logs generated by the Zeek engine.
  • [EXTERNAL_DOWNLOADS]: Provides instructions for installing the Zeek engine via standard package managers (apt, brew) and Docker. It also references the installation of the ja3 package from a well-known organization's repository using the Zeek Package Manager.
  • [SAFE]: Includes legitimate forensic investigation patterns, such as searching for cleartext credentials and sensitive strings in HTTP, FTP, and SMTP logs, which is consistent with its stated purpose as a laboratory reference for protocol analysis.
  • [SAFE]: Utilizes an inline Python script for calculating the entropy of domain names to detect DNS tunneling, as well as custom Zeek scripts for identifying potential command-and-control beaconing behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 03:11 AM
Security Audit — agent-trust-hub — zeek