skills/mukul975/anthropic-cybersecurity-skills/building-soc-playbook-for-ransomware/Gen Agent Trust Hub
building-soc-playbook-for-ransomware
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The
agent.pyscript includes a functioncheck_id_ransomwarethat uploads file samples to an external third-party service (id-ransomware.malwarehunterteam.com). While this is a recognized community tool for identifying ransomware variants, uploading encrypted files (which may contain sensitive data) to external platforms is a data privacy risk in an enterprise environment. - [COMMAND_EXECUTION]: The skill provides numerous high-privilege commands and scripts for host isolation (CrowdStrike/Defender APIs), Active Directory account management (
Disable-ADAccount,Reset-KrbtgtKeys), and forensic artifact collection. These operations are aligned with the skill's purpose but require strict access controls to prevent misuse. - [EXTERNAL_DOWNLOADS]: The skill references and interacts with several well-known and trusted cybersecurity services, including MalwareBazaar (abuse.ch) and the No More Ransom Project. These are legitimate resources used for threat intelligence enrichment.
- [CREDENTIALS_UNSAFE]: The automation script accepts sensitive API tokens and session keys (e.g.,
--cs-token,--splunk-key) as command-line arguments. This can result in credential exposure in system process logs or shell history files. Additionally, the script allows bypassing TLS verification for Splunk connections via theSKIP_TLS_VERIFYenvironment variable, which could facilitate Man-in-the-Middle attacks in production environments. - [PROMPT_INJECTION]: The skill ingests data from external web responses (e.g., from
nomoreransom.orgormalwarehunterteam.com). These untrusted outputs create a surface for indirect prompt injection if the agent processes this content as instructions without proper sanitization. - [SAFE]: There is a discrepancy in the metadata where the
SKILL.mdlists the author as 'mahipal' while theLICENSEfile specifies 'mukul975'. This is a minor inconsistency but does not pose a direct security threat.
Audit Metadata