analyzing-phishing-emails

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive educational content on analyzing phishing emails, emphasizing safety through the use of raw message headers, isolated environments, and indicator defanging.
  • [COMMAND_EXECUTION]: The instructions include command-line examples using established forensics and diagnostic tools such as emldump.py, oledump.py, dig, whois, and exiftool. These are used for static analysis of email structure and external metadata lookups.
  • [EXTERNAL_DOWNLOADS]: The skill recommends using well-known and reputable security services for threat analysis, including urlscan.io, VirusTotal, and PhishTool. These are standard tools in the security industry for safely investigating suspicious URLs and files.
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of ingesting malicious data from phishing emails and incorporates defensive measures, such as explicit instructions to defang indicators and process payloads in isolated VMs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — analyzing-phishing-emails