generating-forensic-timelines-with-hayabusa

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/agent.py invokes the Hayabusa binary via subprocess.run(). The implementation uses argument lists rather than shell strings, which is a recommended practice to mitigate command injection risks.
  • [EXTERNAL_DOWNLOADS]: The skill's documentation provides commands to download the Hayabusa binary and rules from the official Yamato Security GitHub repositories. These are standard, reputable sources for this security tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 09:18 AM
Security Audit — agent-trust-hub — generating-forensic-timelines-with-hayabusa