binwalk
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructions utilize
sudofor system package installation (apt install binwalk), tool setup (python setup.py install), and for administrative tasks during firmware emulation such aschrootand configuring network tap interfaces. - [EXTERNAL_DOWNLOADS]: The skill provides commands to clone source code and utilities from public GitHub repositories, specifically the official
binwalkrepository and theFirmAEfirmware emulation project. - [COMMAND_EXECUTION]: The skill employs
binwalk's custom extraction capability (-D), which executes shell commands likegunzip,lzop, andddon matched binary segments of input files. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted binary firmware images which could contain malicious data structures. It recommends using security-focused flags such as
-n(file count limit) and-j(file size limit) to mitigate the risk of resource exhaustion attacks like zip bombs during recursive extraction. - [DYNAMIC_EXECUTION]: The
-Dflag inbinwalkallows for the dynamic assembly and execution of extraction commands based on signatures found within the analyzed binary blobs.
Audit Metadata