yara-rule-authoring
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides high-quality educational content and tools for YARA-X rule development.
- [SAFE]: Scripts included in the skill (e.g.,
yara_lint.py,atom_analyzer.py) use the legitimateyara-xlibrary for rule validation and analysis. The scripts are well-structured and perform parsing tasks without suspicious side effects. - [SAFE]: The example YARA rules provided correctly demonstrate detection patterns for various malware families and supply chain attacks without including any malicious payloads or exfiltration code.
- [SAFE]: No obfuscation, data exfiltration patterns, or privilege escalation attempts were found. The mention of zero-width characters and other obfuscation techniques is strictly within the context of teaching users how to detect such techniques using YARA.
Audit Metadata