threat-hunter
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No executable code was found. The skill consists entirely of Markdown files providing guidance on threat hunting methodologies, SIEM query construction, and reporting templates.
- [PROMPT_INJECTION]: No attempts to override system prompts, bypass safety filters, or extract system instructions were detected. The instructional language is consistent with professional security operations.
- [DATA_EXFILTRATION]: No network operations, hardcoded credentials, or sensitive file access patterns were identified. The skill describes telemetry analysis within a theoretical SOC environment without providing mechanism for data transfer.
- [REMOTE_CODE_EXECUTION]: There are no remote script downloads (curl|bash), package installations, or dynamic code execution patterns. All references are to internal documentation files.
- [OBFUSCATION]: No Base64, hex encoding, zero-width characters, or other obfuscation techniques were found. All text is in clear-text Markdown.
- [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external data (threat intel and logs), it lacks the execution capabilities (subprocess, eval, file-write) required for a payload to be impactful. Ingestion points are limited to the user's interaction with the agent.
Audit Metadata