skills/aeondave/malskill/ftk-imager/Gen Agent Trust Hub

ftk-imager

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill guides the user to access and capture highly sensitive system data, including volatile memory (\.\PHYSICALMEMORY) and physical disk drives (\.\PhysicalDrive0). While intended for forensic acquisition, this provides a mechanism for exposing the entire state of the system.- [PRIVILEGE_ESCALATION]: Numerous commands require administrative or root privileges, such as the use of sudo for mounting images and insmod for loading kernel modules into the system. Windows memory acquisition also requires elevated privileges to access physical memory device objects.- [REMOTE_CODE_EXECUTION]: The skill provides instructions to download, compile, and execute code from an external repository. In references/acquisition-tricks-and-flow.md, it directs users to git clone the LiME repository, use make to build the kernel module, and insmod to load it into the running kernel.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from untrusted disk images and memory dumps. 1. Ingestion points: File extraction and browsing in the FTK Imager evidence tree as described in SKILL.md. 2. Boundary markers: No markers or explicit warnings to ignore instructions found within analyzed forensic artifacts. 3. Capability inventory: Ability to execute shell commands, mount filesystems, and run external scripts like Volatility3. 4. Sanitization: No evidence of data sanitization before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — ftk-imager