analyzing-cyber-kill-chain
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides purely instructional content for mapping adversary actions to the Cyber Kill Chain framework. It contains no scripts, binaries, or automated tools.
- [SAFE]: No prompt injection, data exfiltration, or persistence mechanisms were detected in the instructions or metadata.
- [PROMPT_INJECTION]: The skill instructions involve processing external data sources such as incident reports and forensic artifacts which represents a potential surface for indirect prompt injection.
- Ingestion points: 'incident timeline with forensic artifacts' and 'Post-incident report' mentioned in the workflow (SKILL.md).
- Boundary markers: None specified in the workflow.
- Capability inventory: None. The skill does not perform any automated actions, subprocess calls, file-system writes, or network operations.
- Sanitization: None defined in the documentation.
Audit Metadata