investigating-phishing-email-incident

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to well-known security and technology services including VirusTotal, URLScan.io, MalwareBazaar (abuse.ch), and Microsoft Graph API. These operations are essential for the skill's stated purpose of threat investigation and indicator enrichment.
  • [COMMAND_EXECUTION]: Documentation and scripts include administrative PowerShell commands (e.g., Compliance Search and Purge, Password Resets) and Python scripts for forensic analysis. These high-privilege operations are appropriate for SOC incident response workflows.
  • [DATA_EXFILTRATION]: While the skill transmits data (URLs, file hashes) to external APIs, these are reputable security services used for reputation lookups. No evidence of unauthorized data exfiltration or credential harvesting was found.
  • [PROMPT_INJECTION]: The skill processes untrusted data from email headers and bodies (.eml files). While this represents a surface for indirect prompt injection, the provided scripts use standard parsing libraries and perform specific forensic tasks without passing untrusted content directly into high-risk agent instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 09:09 AM
Security Audit — agent-trust-hub — investigating-phishing-email-incident