mid-engagement-ir-detection

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [SAFE]: The skill provides a methodology for red-team engagements, focusing on documenting state changes as positive security findings.- [COMMAND_EXECUTION]: The skill includes shell scripts that use standard utilities such as curl, grep, and bc for monitoring target response times and auditing M365 lockout logs. These actions are consistent with the stated purpose of operational monitoring.- [DYNAMIC_EXECUTION]: Employs inline Python scripts to calculate timing deltas and analyze local engagement logs. These scripts are static, use standard libraries (json, time), and do not process untrusted remote input in a way that suggests a vulnerability.- [DATA_EXPOSURE]: Accesses local engagement log files (e.g., engagement_log/baseline.json) to establish baselines and track changes. There is no evidence of exfiltration of sensitive system files or credentials to unauthorized external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:31 AM
Security Audit — agent-trust-hub — mid-engagement-ir-detection