mobile-ctf
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted mobile artifacts (APK, IPA, Android backups) that could contain malicious payloads designed to influence agent behavior.
- Ingestion points: User-supplied artifacts such as 'target.apk' and 'backup.ab' (SKILL.md, references/android-backup-forensics.md).
- Boundary markers: Absent; there are no instructions to delimit or treat artifact content as untrusted data.
- Capability inventory: Subprocess execution (shell commands), file system writes (extraction), and network access (curl).
- Sanitization: Absent; content is processed directly using tools like strings, grep, and custom Python scripts.
- [EXTERNAL_DOWNLOADS]: The skill provides commands to download and use security tools from third-party GitHub repositories not included in the verified list.
- Evidence: References to github.com/skylot/jadx, github.com/Perfare/Il2CppDumper, and github.com/nelenkov/android-backup-extractor.
- [COMMAND_EXECUTION]: The skill relies on executing various shell commands to perform analysis of mobile binary artifacts.
- [DYNAMIC_EXECUTION]: The skill uses Python script generation patterns (python3 -c and heredocs) for local data extraction tasks.
- [DATA_EXFILTRATION]: Instructs the agent to perform network requests to external Firebase domains to check for exposed data (SKILL.md).
Audit Metadata