malware-ctf
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructions and scripts use
sudofor various tasks:\n sudo arpspoofandsudo routeinreferences/c2-and-protocols.mdfor ARP spoofing and network routing.\nsudo tcpdumpinreferences/c2-and-protocols.mdandreferences/scripts-and-obfuscation.mdfor packet capture.\nsudo straceinreferences/scripts-and-obfuscation.mdfor system call tracing.\n- [COMMAND_EXECUTION]: Python code snippets utilizesubprocess.runandsubprocess.Popento execute system-level commands liketcpdumpandstracefor monitoring malware behavior.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted artifacts such as malware samples, scripts, and PCAP files. While it provides methodologies for analysis, the ingestion of adversarial data combined with high-privilege capabilities (sudo,subprocess) creates an attack surface for indirect prompt injection.\n- Ingestion points: Malware samples, scripts, memory dumps, and network captures provided by users or external sources.\n
- Boundary markers: The instructions recommend running dynamic analysis in isolation (VM/Docker) but do not specify prompt-level boundaries for processing artifact content.\n
- Capability inventory: File system access, network manipulation (
arpspoof), packet sniffing (tcpdump), system tracing (strace), and library hooking (frida,unicorn).\n - Sanitization: None specified for the content of processed artifacts.\n- [DATA_EXFILTRATION]: The skill interacts with external services for analysis and evidence recovery:\n
- Fetches data and updates from Telegram's API (
api.telegram.org) using therequestslibrary inreferences/c2-and-protocols.mdfor evidence recovery tasks.\n - Performs VirusTotal API lookups (
virustotal.com) inreferences/static-and-dynamic-triage.mdfor file identification.
Audit Metadata