skills/aeondave/malskill/game-ctf/Gen Agent Trust Hub

game-ctf

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted binary data from game artifacts, assets, and network captures.
  • Ingestion points: Game binaries (.exe, ELF, .so, .dll), Unity asset files (.assets, .dmp), and network PCAP files.
  • Boundary markers: No explicit markers or delimiters are used to isolate content extracted from untrusted artifacts.
  • Capability inventory: File system write operations (open(..., 'wb')), network socket communication (socket.socket()), and direct process memory access via /proc/<pid>/mem.
  • Sanitization: Extracted data, such as string literals or metadata, is used directly in analysis logic without sanitization.
  • [COMMAND_EXECUTION]: The skill includes instructions for high-impact system operations necessary for reverse engineering.
  • Binary Patching: Provides Python snippets to modify executable logic, such as overwriting instructions at specific offsets to bypass win conditions.
  • Memory Manipulation: Contains instructions for reading and writing to process memory via the Linux proc filesystem and using memory scanning tools.
  • [DYNAMIC_EXECUTION]: The skill generates and executes logic at runtime using shell heredocs.
  • Evidence: Multiple instances of `python3
  • <<'EOF'` are utilized to execute dynamically generated scripts for process memory modification, binary patching, and network protocol interaction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — game-ctf