extracting-browser-history-artifacts
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Employs standard shell commands such as
mount,cp, andsqlite3to interact with disk images and perform database queries on forensic artifacts. These operations are restricted to a local investigation environment. - [EXTERNAL_DOWNLOADS]: Instructs the installation of the
pyhindsightPython package, which is a well-known and trusted open-source tool for parsing Chromium-based browser history and cache. - [SAFE]: While the skill accesses sensitive data files (like Chrome Cookies and Login Data), it does so within the context of a digital forensic investigation. No network operations or exfiltration patterns were identified that would suggest unauthorized data transfer.
Audit Metadata