skills/mukul975/anthropic-cybersecurity-skills/building-ioc-enrichment-pipeline-with-opencti/Gen Agent Trust Hub
building-ioc-enrichment-pipeline-with-opencti
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements an automated pipeline that ingests untrusted data (Indicators of Compromise such as IPs, domains, and hashes) which is سپس used to interact with external APIs and update the OpenCTI knowledge graph. This architecture presents an indirect prompt injection surface. Evidence Chain: (1) Ingestion points: User input and automated message processing in
scripts/process.pyandSKILL.md. (2) Boundary markers: Absent. (3) Capability inventory: Network requests using therequestslibrary and database modifications viapyctiAPI calls. (4) Sanitization: Basic validation is performed via regex in theclassify_iocfunction. - [PROMPT_INJECTION]: An inconsistency was detected in the skill metadata where the author name in the YAML frontmatter ('mahipal') does not align with the copyright holder in the LICENSE file ('mukul975'), which may indicate deceptive metadata or a configuration error.
Audit Metadata