detect-lateral-movement

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate security tool for log correlation. It adheres to its stated purpose of detecting lateral movement based on OCSF and MITRE ATT&CK frameworks with clear, documented logic.
  • [COMMAND_EXECUTION]: Analysis of src/detect.py shows no use of dangerous functions like os.system, subprocess.run, or eval. The script processes data through standard input/output streams and basic file operations common for CLI utilities.
  • [EXTERNAL_DOWNLOADS]: No network requests or external code downloads were identified in the source code. The skill operates entirely on local data provided by the user.
  • [DATA_EXFILTRATION]: There is no evidence of data being sent to external servers. The skill processes audit and flow logs locally and outputs structured detection findings to standard output.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or tokens were detected. Configuration for detection thresholds is handled through environment variables, which is a standard practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — detect-lateral-movement