forensics-checklist

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill outlines standardized procedures for forensic acquisition following NIST SP 800-86 and RFC 3227 guidelines.\n- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface as it is designed to analyze untrusted forensic data (logs, memory dumps). This risk is mitigated by explicit instructions in Section 8 that forbid the agent from executing commands or following directives found in forensic artifacts. Ingestion points: Target files/directories provided via arguments. Boundary markers: Structured report format defined in Section 5. Capability inventory: Restricted access to Read, Grep, and Glob tools. Sanitization: Mandatory safety notice for the agent.\n- [SAFE]: No evidence of data exfiltration, hardcoded credentials, or malicious persistence mechanisms was detected.\n- [SAFE]: All commands and tools referenced (e.g., dc3dd, WinPmem, AWS/Azure/GCP CLIs) are standard industry utilities for forensic collection and aligned with the skill's legitimate purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:07 AM
Security Audit — agent-trust-hub — forensics-checklist