producing-threat-intelligence

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive educational content on CTI best practices and methodologies.
  • [EXTERNAL_DOWNLOADS]: References external data sources including crt.sh, a well-known certificate transparency log, and defuddle.md, a utility for fetching markdown content.
  • [COMMAND_EXECUTION]: Provides standard CLI examples for curl, jq, shodan, and censys to demonstrate indicator enrichment.
  • [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection where untrusted external data enters the agent context. Ingestion points: External advisories and certificate data fetched via curl in SKILL.md. Boundary markers: Absent from instructions. Capability inventory: Subprocess calls to curl, shodan, and censys in SKILL.md. Sanitization: Absent. The risk is minimized by the skill's warnings against processing sensitive data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — producing-threat-intelligence