forensics-ctf
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external artifacts, including disk images, memory dumps, network captures (PCAP), and various steganographic files, which could potentially contain malicious instructions.
- Ingestion points: Forensic artifact processing workflows detailed throughout the reference files, such as
references/network-triage.mdandreferences/advanced-disk-and-memory.md. - Boundary markers: The instructions do not define explicit boundary markers or instructions to ignore embedded content when parsing these untrusted files.
- Capability inventory: The skill provides workflows involving significant system capabilities, including file system mounting (
sudo mount), direct block level access (dd), network analysis (tshark), and numerous specialized forensics tools. - Sanitization: There is no mention of automated sanitization or filtering of the content within the artifacts being analyzed.
- [COMMAND_EXECUTION]: The skill provides extensive workflows for executing forensics tools and shell commands (e.g.,
volatility3,sleuth-kit,binwalk,tshark). These are legitimate within the context of CTF forensics analysis and professional offensive methodology. - [EXTERNAL_DOWNLOADS]: The reference material provides instructions for downloading and installing established security tools and libraries from well-known repositories (e.g.,
John the Ripper,FemtoZip,bkcrack) for forensic recovery tasks.
Audit Metadata