raven-zero-day-hunter
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skills implement the 'Compositional Defense Pipelines' (CDP) contract and 'MDASH' framework, which use rigid instructional constraints and validation stages to ensure the agent adheres to defender-only protocols and refuses to generate exploits.
- [COMMAND_EXECUTION]: Legitimate execution of security tools (YARA, Semgrep, Ghidra, radare2, Nuclei) and development utilities (git, gh) is core to the suite's purpose of analyzing codebases and binaries.
- [EXTERNAL_DOWNLOADS]: The skills interact with well-known security databases (NVD, OSV) and development platforms (GitHub, GitLab) to fetch vulnerability information and target artifacts for analysis.
- [DATA_EXFILTRATION]: Alerting and logging data is sent to configured enterprise sinks (Kafka, Prometheus, SIEM webhooks), which is standard behavior for DevSecOps tooling.
Audit Metadata