emulation-technique
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a technical methodology for reverse engineering and emulation. It contains no malicious patterns, obfuscation, or unauthorized data access commands. All external tools mentioned (QEMU, Qiling, Renode, etc.) are standard, reputable utilities for security research.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted artifacts (e.g., binaries, firmware) which could potentially contain adversarial instructions. However, the skill proactively mitigates this by instructing the agent to use isolated VMs or containers, avoid sharing host secrets, and restrict network traffic to localhost. This represents a robust security posture for the intended use case.
- [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill mentions network tools like
curl,nc, andssh, it does so exclusively for validating rehosted services onlocalhostor within isolated labs. It explicitly warns against exposing services broadly and advises against sharing secrets with the guest environment. - [COMMAND_EXECUTION]: The skill provides numerous command-line examples for interacting with emulators and extraction tools. These are legitimate examples tailored to the skill's purpose and are intended to be executed against the target artifact in a controlled, sandboxed environment.
Audit Metadata