skills/aeondave/malskill/hardware-ctf/Gen Agent Trust Hub

hardware-ctf

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data sources, creating a surface for indirect prompt injection attacks.
  • Ingestion points: The skill processes logic analyzer captures (.sal, sigrok, CSV), firmware images (SPI flash dumps, UEFI blobs, binaries), PCAPs (USB, Bluetooth, CAN), RF/IQ samples, and CAD/G-code artifacts as defined in SKILL.md and references/hardware-artifact-workflow.md.
  • Boundary markers: The instructions lack specific guidance on using boundary markers or delimiters when presenting the extracted content (e.g., strings from firmware or decoded bus traffic) to the agent context.
  • Capability inventory: The skill routes tasks to powerful tools including saleae-logic-2, sigrok-cli, binwalk, ghidra, radare2, binaryninja, QEMU, and OpenOCD for extraction, disassembly, and emulation (SKILL.md).
  • Sanitization: There is no mention of sanitizing or filtering the output of these tools before the agent processes them. Malicious instructions embedded within a hardware artifact (e.g., inside a firmware string or a logic trace packet) could influence the agent's behavior during the analysis phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — hardware-ctf