pwn-ctf
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill contains extensive documentation and methodology for exploiting privilege escalation vulnerabilities on target systems, such as overwriting
modprobe_pathorcore_patternin the Linux kernel and SEH bypasses in Windows. These techniques are presented as instructional material for CTF and lab environments.\n- [COMMAND_EXECUTION]: The provided references describe numerous methods to achieve arbitrary command execution on target platforms, including ROP chains forexecve, shellcode construction, and exploiting interpreters or emulators. These examples are consistent with the skill's primary offensive security purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with and process untrusted binary artifacts and remote network services, creating a surface for potential indirect prompt injection. While inherent to the task of binary exploitation, malicious inputs from a target could theoretically attempt to influence the agent's actions.\n - Ingestion points: Untrusted challenge binaries and remote socket data processed via the methodology in
SKILL.md.\n - Boundary markers: No explicit delimiters or instructions to ignore embedded data commands were found.\n
- Capability inventory: The skill utilizes powerful tools such as
pwntools,GDB,radare2, andghidrafor system interaction and binary analysis.\n - Sanitization: Binary and string data from untrusted sources are not sanitized before being used in the exploitation workflow.\n- [DYNAMIC_EXECUTION]: A core component of the skill involves the dynamic generation, inspection, and execution of machine code payloads and the use of debuggers to modify process memory at runtime.
Audit Metadata