crypto-technique

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an indirect prompt injection attack surface by processing external, untrusted cryptographic artifacts (ciphertexts, public keys, signatures, and oracle responses) which are then used as inputs for Python and SageMath scripts.
  • Ingestion points: Untrusted data enters the agent context during Phase 1 (Problem diagnosis) via source code review, key material extraction, and oracle characterization.
  • Boundary markers: There are no specific instructions to use delimiters or ignore embedded instructions within the processed cryptographic data.
  • Capability inventory: The skill utilizes significant execution capabilities including Python scripts, SageMath models, Z3 SMT solving, and specialized tools like RsaCtfTool and Hashcat.
  • Sanitization: No sanitization or validation of the content of cryptographic artifacts is described beyond parsing their mathematical properties.
  • [EXTERNAL_DOWNLOADS]: The skill references several external repositories and recommends the installation of specialized Python packages to facilitate cryptographic attacks.
  • The instructions recommend installing z3-solver, not_random, and hashpumpy via pip for specific attack vectors like SMT solving, MT19937 recovery, and hash length extension.
  • Technical references point to third-party GitHub repositories for specialized cryptanalytic implementations, including jvdsn/crypto-attacks for Smart's attack and fionn/batch-gcd for Batch GCD implementations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — crypto-technique