analyzing-phishing-emails
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive educational content on analyzing phishing emails, emphasizing safety through the use of raw message headers, isolated environments, and indicator defanging.
- [COMMAND_EXECUTION]: The instructions include command-line examples using established forensics and diagnostic tools such as
emldump.py,oledump.py,dig,whois, andexiftool. These are used for static analysis of email structure and external metadata lookups. - [EXTERNAL_DOWNLOADS]: The skill recommends using well-known and reputable security services for threat analysis, including
urlscan.io,VirusTotal, andPhishTool. These are standard tools in the security industry for safely investigating suspicious URLs and files. - [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of ingesting malicious data from phishing emails and incorporates defensive measures, such as explicit instructions to defang indicators and process payloads in isolated VMs.
Audit Metadata