donut
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides various examples of running the
donutcommand-line utility to transform .NET and native Windows executables into shellcode. - [EXTERNAL_DOWNLOADS]: The skill references the installation of the
donut-shellcodepackage from the Python Package Index (PyPI) and cloning from a git repository. - [PROMPT_INJECTION]: The tool is designed to ingest external binary files and parameters to generate executable output. While this represents a data ingestion surface, it is consistent with the tool's primary purpose. * Ingestion points: Input files (-f) and parameters (-p) in SKILL.md. * Capability inventory: Shellcode generation and file system output across CLI and Python modules. * Boundary markers: None present; the tool directly transforms input into execution payloads. * Sanitization: None documented, as the tool's function is to encapsulate input binaries as-is.
Audit Metadata