hardware-ctf
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data sources, creating a surface for indirect prompt injection attacks.
- Ingestion points: The skill processes logic analyzer captures (.sal, sigrok, CSV), firmware images (SPI flash dumps, UEFI blobs, binaries), PCAPs (USB, Bluetooth, CAN), RF/IQ samples, and CAD/G-code artifacts as defined in
SKILL.mdandreferences/hardware-artifact-workflow.md. - Boundary markers: The instructions lack specific guidance on using boundary markers or delimiters when presenting the extracted content (e.g., strings from firmware or decoded bus traffic) to the agent context.
- Capability inventory: The skill routes tasks to powerful tools including
saleae-logic-2,sigrok-cli,binwalk,ghidra,radare2,binaryninja,QEMU, andOpenOCDfor extraction, disassembly, and emulation (SKILL.md). - Sanitization: There is no mention of sanitizing or filtering the output of these tools before the agent processes them. Malicious instructions embedded within a hardware artifact (e.g., inside a firmware string or a logic trace packet) could influence the agent's behavior during the analysis phase.
Audit Metadata