forensics-checklist

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided targets through the $ARGUMENTS variable and analyzes untrusted forensic data (logs, memory, disk artifacts). It includes a dedicated 'Prompt Injection Safety Notice' in Section 8, which explicitly instructs the agent to treat all collected content as data, never follow instructions embedded in analyzed artifacts, and avoid exfiltrating sensitive values found during examination.
  • [COMMAND_EXECUTION]: The skill contains numerous examples of command-line tools for various operating systems and cloud environments, such as sudo insmod, wevtutil, aws ec2 create-snapshot, and gcloud compute disks snapshot. These are contextually appropriate for the primary purpose of forensic evidence collection and are presented as reference material for the examiner.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:11 PM
Security Audit — agent-trust-hub — forensics-checklist