pwntools
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of the
process()function to launch and control local binaries. It also includes instructions for attaching the GDB debugger to running processes usinggdb.attach(). These features are standard components of the pwntools library for analyzing and exploiting software vulnerabilities. - [DYNAMIC_EXECUTION]: The skill provides examples of using the
asm()function to compile assembly instructions into machine-executable shellcode at runtime. It also demonstrates the use ofshellcraftto generate common shellcode payloads for various architectures. This capability is expected for a binary exploitation framework. - [INDIRECT_PROMPT_INJECTION]: The skill contains patterns for receiving and parsing data from remote network services using
remote()andrecv*methods. This creates a potential surface for indirect prompt injection if the agent processes malicious instructions embedded in a service's response. - Ingestion points: Network socket receive calls such as
io.recvline(),io.recvuntil(), andio.recvregex()documented inSKILL.mdandreferences/service-interaction.md. - Boundary markers: The provided code snippets use delimiters like newlines and specific prompt characters to isolate incoming data.
- Capability inventory: The skill enables local process execution, network communication via TCP and SSH, and runtime assembly compilation.
- Sanitization: No specific filtering or sanitization of external service output is included in the provided templates, as the primary use case is interaction with challenge servers during security competitions.
- [REMOTE_CODE_EXECUTION]: The skill includes instructions to install the 'pwntools' library from the official Python package registry. This is a standard and expected dependency for the skill's functionality.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
Audit Metadata