skills/aeondave/malskill/frida/Gen Agent Trust Hub

frida

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill demonstrates the use of Frida's CModule API to compile C source code strings directly into the memory of a target process at runtime for performance-critical instrumentation.
  • Evidence: references/hooks-catalog.md shows new CModule() usage for high-performance instruction tracing and function patching.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands and the adb utility to set up the instrumentation environment and interact with processes.
  • Evidence: SKILL.md includes commands for listing processes (frida-ps), spawning binaries (frida -f), and pushing the instrumentation server to Android devices via adb push.
  • [DATA_EXFILTRATION]: Instructions and scripts are provided to monitor and capture sensitive data such as passwords, cryptographic keys, and network payloads from external processes.
  • Evidence: references/hooks-catalog.md contains a hook for the read function that uses a regular expression to search for sensitive strings like 'password', 'secret', 'key', or 'token' in data buffers.
  • [PRIVILEGE_ESCALATION]: The skill includes commands to modify file permissions on a device to allow for the execution of the instrumentation server.
  • Evidence: SKILL.md provides an adb shell chmod 755 command for the frida-server binary.
  • [EXTERNAL_DOWNLOADS]: The skill references external binaries hosted on GitHub for the instrumentation toolkit's server-side component.
  • Evidence: SKILL.md and references/android-ios.md point to the official GitHub releases page for frida-server downloads.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from untrusted external processes, which could potentially contain malicious instructions targeting the agent.
  • Ingestion points: Data is read from process memory and system calls using Interceptor.attach and Memory.readByteArray in SKILL.md and references/hooks-catalog.md.
  • Boundary markers: Absent.
  • Capability inventory: Process injection, memory modification, and shell command execution are detailed across all scripts in the skill.
  • Sanitization: Absent. Content from hooked processes is logged directly to the console without filtering or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — frida