ftk-imager
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill guides the user to access and capture highly sensitive system data, including volatile memory (\.\PHYSICALMEMORY) and physical disk drives (\.\PhysicalDrive0). While intended for forensic acquisition, this provides a mechanism for exposing the entire state of the system.- [PRIVILEGE_ESCALATION]: Numerous commands require administrative or root privileges, such as the use of
sudofor mounting images andinsmodfor loading kernel modules into the system. Windows memory acquisition also requires elevated privileges to access physical memory device objects.- [REMOTE_CODE_EXECUTION]: The skill provides instructions to download, compile, and execute code from an external repository. Inreferences/acquisition-tricks-and-flow.md, it directs users togit clonethe LiME repository, usemaketo build the kernel module, andinsmodto load it into the running kernel.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from untrusted disk images and memory dumps. 1. Ingestion points: File extraction and browsing in the FTK Imager evidence tree as described inSKILL.md. 2. Boundary markers: No markers or explicit warnings to ignore instructions found within analyzed forensic artifacts. 3. Capability inventory: Ability to execute shell commands, mount filesystems, and run external scripts like Volatility3. 4. Sanitization: No evidence of data sanitization before processing.
Audit Metadata