analyzing-network-traffic

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for using a wide range of standard network analysis utilities, including tcpdump, tshark, zeek, editcap, mergecap, sha256sum, and suricata. These commands are used correctly for forensic capture, evidence hashing, and protocol analysis.
  • [DATA_EXFILTRATION]: While the skill contains sections dedicated to 'Exfiltration Hunting,' it does so by providing defensive methodologies to detect large outbound transfers. There is no code or instruction to exfiltrate local data or perform unauthorized network transfers.
  • [SAFE]: The skill is well-documented and focuses on defensive security operations. It does not employ obfuscation, remote code execution from unknown sources, or privilege escalation. All examples use placeholder domains (e.g., evil.com) or well-known service endpoints (e.g., s3.amazonaws.com) in a diagnostic context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — analyzing-network-traffic