tracking-threat-actor-infrastructure

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill queries several well-known and trusted threat intelligence providers, including Shodan, VirusTotal, SecurityTrails, and crt.sh. These operations are essential to the skill's documented purpose of infrastructure tracking.\n- [SAFE]: All identified network operations target established security services. Sensitive API keys are managed using placeholders, and no evidence of code obfuscation, persistence, or privilege escalation was found.\n- [CREDENTIALS_UNSAFE]: The script scripts/agent.py contains a hardcoded 'demo' API key for SecurityTrails. This is a public key intended for demonstration purposes and does not pose a security risk to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 02:29 PM