skills/aeondave/malskill/ics-ctf/Gen Agent Trust Hub

ics-ctf

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes command-line examples for common security and industrial tools such as tshark, nmap, can-utils, and mosquitto_sub. These are provided for protocol analysis and auditing purposes within an authorized CTF or lab context.
  • [PRIVILEGE_ESCALATION]: Reference files provide instructions for using sudo to set up virtual CAN interfaces (vcan) and iptables rules for traffic redirection. These are standard administrative actions for network simulation and security research in controlled environments.
  • [REMOTE_CODE_EXECUTION]: The skill references various remote code execution (RCE) techniques and malware variants (e.g., Industroyer, Stuxnet, DynoWiper) within the references/incidents.md file. These mentions are strictly educational, serving as historical context and behavioral fingerprints for threat actor recognition, rather than functional triggers.
  • [DATA_EXFILTRATION]: Documentation describes various data exfiltration tactics used by adversaries (e.g., certutil -encode, Slack webhooks, and Dropbox staging) to help users identify indicators of compromise (IOCs). The skill does not implement any exfiltration logic of its own.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — ics-ctf