frida
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill demonstrates the use of Frida's
CModuleAPI to compile C source code strings directly into the memory of a target process at runtime for performance-critical instrumentation. - Evidence:
references/hooks-catalog.mdshowsnew CModule()usage for high-performance instruction tracing and function patching. - [COMMAND_EXECUTION]: The skill utilizes shell commands and the
adbutility to set up the instrumentation environment and interact with processes. - Evidence:
SKILL.mdincludes commands for listing processes (frida-ps), spawning binaries (frida -f), and pushing the instrumentation server to Android devices viaadb push. - [DATA_EXFILTRATION]: Instructions and scripts are provided to monitor and capture sensitive data such as passwords, cryptographic keys, and network payloads from external processes.
- Evidence:
references/hooks-catalog.mdcontains a hook for thereadfunction that uses a regular expression to search for sensitive strings like 'password', 'secret', 'key', or 'token' in data buffers. - [PRIVILEGE_ESCALATION]: The skill includes commands to modify file permissions on a device to allow for the execution of the instrumentation server.
- Evidence:
SKILL.mdprovides anadb shell chmod 755command for thefrida-serverbinary. - [EXTERNAL_DOWNLOADS]: The skill references external binaries hosted on GitHub for the instrumentation toolkit's server-side component.
- Evidence:
SKILL.mdandreferences/android-ios.mdpoint to the official GitHub releases page forfrida-serverdownloads. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from untrusted external processes, which could potentially contain malicious instructions targeting the agent.
- Ingestion points: Data is read from process memory and system calls using
Interceptor.attachandMemory.readByteArrayinSKILL.mdandreferences/hooks-catalog.md. - Boundary markers: Absent.
- Capability inventory: Process injection, memory modification, and shell command execution are detailed across all scripts in the skill.
- Sanitization: Absent. Content from hooked processes is logged directly to the console without filtering or escaping.
Audit Metadata