skills/aeondave/malskill/malware-ctf/Gen Agent Trust Hub

malware-ctf

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructions and scripts use sudo for various tasks:\n
  • sudo arpspoof and sudo route in references/c2-and-protocols.md for ARP spoofing and network routing.\n
  • sudo tcpdump in references/c2-and-protocols.md and references/scripts-and-obfuscation.md for packet capture.\n
  • sudo strace in references/scripts-and-obfuscation.md for system call tracing.\n- [COMMAND_EXECUTION]: Python code snippets utilize subprocess.run and subprocess.Popen to execute system-level commands like tcpdump and strace for monitoring malware behavior.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted artifacts such as malware samples, scripts, and PCAP files. While it provides methodologies for analysis, the ingestion of adversarial data combined with high-privilege capabilities (sudo, subprocess) creates an attack surface for indirect prompt injection.\n
  • Ingestion points: Malware samples, scripts, memory dumps, and network captures provided by users or external sources.\n
  • Boundary markers: The instructions recommend running dynamic analysis in isolation (VM/Docker) but do not specify prompt-level boundaries for processing artifact content.\n
  • Capability inventory: File system access, network manipulation (arpspoof), packet sniffing (tcpdump), system tracing (strace), and library hooking (frida, unicorn).\n
  • Sanitization: None specified for the content of processed artifacts.\n- [DATA_EXFILTRATION]: The skill interacts with external services for analysis and evidence recovery:\n
  • Fetches data and updates from Telegram's API (api.telegram.org) using the requests library in references/c2-and-protocols.md for evidence recovery tasks.\n
  • Performs VirusTotal API lookups (virustotal.com) in references/static-and-dynamic-triage.md for file identification.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — malware-ctf