monitoring-darkweb-sources

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to established cybersecurity and threat intelligence services, including Have I Been Pwned (HIBP), DeHashed, and Ransomware.live. These operations are restricted to searching for threat data and do not involve downloading or executing untrusted code.
  • [COMMAND_EXECUTION]: The documentation includes standard shell commands (curl) for searching public paste sites. These are provided as examples for manual investigation workflows and do not involve automated execution of dangerous or hidden commands.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No exfiltration of sensitive organizational data was detected. The skill uses GET requests to query APIs for publicly reported breach data based on keywords provided by the user. It correctly advises the use of environment variables for API authentication tokens.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external intelligence feeds (Ransomware.live and HIBP). While this represents a theoretical ingestion surface for untrusted data, the risk is negligible as the data is used for generating human-readable reports and does not influence high-privilege operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 09:12 AM
Security Audit — agent-trust-hub — monitoring-darkweb-sources