analyzing-command-and-control-communication

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions suggest the installation of 'cobalt-strike-parser' for configuration extraction and provide functions to query well-known threat intelligence services such as Shodan and VirusTotal.
  • [COMMAND_EXECUTION]: The skill provides Python scripts and shell commands for analyzing network traffic captures (PCAPs) and generating Suricata IDS rules based on identified traffic patterns.
  • [SAFE]: All external domains and IPs mentioned in the documentation (e.g., malicious.com) are explicitly labeled as placeholders or indicators for analysis purposes, consistent with the skill's defensive intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 06:44 PM