agency-threat-intelligence-analyst

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides functional and legitimate templates for cyber security operations, including YARA rules for detecting Cobalt Strike and Sigma rules for identifying Kerberoasting and malicious PowerShell usage. These are industry-standard detection formats and do not contain executable malicious code.
  • [SAFE]: The included Python script for IOC (Indicator of Compromise) enrichment is self-contained and uses standard Python libraries (json, re, uuid, ipaddress). It performs local data transformation (STIX 2.1 and CSV export) and does not perform any network requests or file system modifications.
  • [SAFE]: While the skill's persona involves monitoring external sources like threat feeds and dark web forums—which naturally introduces a surface for indirect prompt injection—the instructions emphasize rigorous analytical standards such as confidence assessments, corroboration across multiple sources, and the use of the Admiralty Code. The skill lacks dangerous capabilities (like automated network exfiltration or shell execution of ingested data) that would make this surface exploitable.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:58 PM
Security Audit — agent-trust-hub — agency-threat-intelligence-analyst