gdb
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and execute a script from a remote URL directly into a shell sub-process.
- Evidence:
bash -c "$(curl -fsSL https://gef.blah.cat/sh)"found inSKILL.md. - [PRIVILEGE_ESCALATION]: The skill uses
sudoto acquire administrative permissions for package installation and system configuration. - Evidence:
sudo apt-get install -y gdbandecho 0 | sudo tee /proc/sys/kernel/randomize_va_spacefound inSKILL.mdandreferences/malware-debugging.md. - [EXTERNAL_DOWNLOADS]: The skill downloads external repositories and scripts to the local system from sources that are not categorized as trusted vendors.
- Evidence:
git clone https://github.com/pwndbg/pwndbgandcurl -fsSL https://gef.blah.cat/sh. - [DYNAMIC_EXECUTION]: The skill utilizes GDB's Python API to define and execute scripts that dynamically interact with process memory, registers, and execution flow.
- Evidence: Python scripts in
SKILL.mdandreferences/scripting.mdusinggdb.execute(),frame.read_register(), andinf.write_memory(). - [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is analyzing untrusted binary data (malware), creating a surface where malicious input could influence agent behavior.
- Ingestion points:
gdb -q ./binaryandread_memory()calls inSKILL.mdandreferences/scripting.md. - Boundary markers: None present.
- Capability inventory: Shell access, memory manipulation, file system writes, and network tracing.
- Sanitization: None present.
Recommendations
- HIGH: Downloads and executes remote code from: https://gef.blah.cat/sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata