raven-zero-day-hunter

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skills implement the 'Compositional Defense Pipelines' (CDP) contract and 'MDASH' framework, which use rigid instructional constraints and validation stages to ensure the agent adheres to defender-only protocols and refuses to generate exploits.
  • [COMMAND_EXECUTION]: Legitimate execution of security tools (YARA, Semgrep, Ghidra, radare2, Nuclei) and development utilities (git, gh) is core to the suite's purpose of analyzing codebases and binaries.
  • [EXTERNAL_DOWNLOADS]: The skills interact with well-known security databases (NVD, OSV) and development platforms (GitHub, GitLab) to fetch vulnerability information and target artifacts for analysis.
  • [DATA_EXFILTRATION]: Alerting and logging data is sent to configured enterprise sinks (Kafka, Prometheus, SIEM webhooks), which is standard behavior for DevSecOps tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 10:45 PM
Security Audit — agent-trust-hub — raven-zero-day-hunter