forensics-assist

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides command-line templates for executing forensics tools like Volatility 3, Plaso (log2timeline.py, psort.py), and Eric Zimmerman's tools for artifact parsing.\n- [EXTERNAL_DOWNLOADS]: The documentation references and links to various reputable third-party security tools and official organizations such as the Volatility Foundation, NIST, SANS, and MITRE.\n- [PROMPT_INJECTION]: The skill involves processing external data (memory dumps, disk images, logs), creating a surface for indirect prompt injection where an attacker could place instructions inside forensic artifacts.\n
  • Ingestion points: Processes forensic images (mem.raw, disk.E01) and OS artifacts (event logs, MFT).\n
  • Boundary markers: None specified for the analysis output.\n
  • Capability inventory: Shell command execution for forensics utilities.\n
  • Sanitization: No explicit sanitization or validation of artifact content is described.\n- [NO_CODE]: This skill is entirely instructional and does not contain any executable scripts, binaries, or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:30 PM
Security Audit — agent-trust-hub — forensics-assist