skills/aeondave/malskill/reverse-ctf/Gen Agent Trust Hub

reverse-ctf

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data in the form of compiled binaries, mobile applications, firmware blobs, and obfuscated scripts.
  • Ingestion points: The skill explicitly instructs the agent to process various binary artifacts and custom VM bytecodes during CTF tasks.
  • Capability inventory: The agent is provided with powerful diagnostic and manipulation tools including debuggers (GDB), disassemblers (Ghidra), dynamic instrumentation frameworks (Frida), and binary patching libraries (pwntools).
  • Boundary markers: The skill does not define specific delimiters for wrapping untrusted binary data or its decompiled/disassembled output within the agent's context, which is common in technical reference materials.
  • Sanitization: There is no specific instruction for the agent to sanitize or filter the results derived from analyzing these potentially adversarial artifacts.
  • [COMMAND_EXECUTION]: The skill provides a large variety of command-line examples for performing technical triage and binary analysis.
  • Evidence: Reference files like references/platforms.md and references/tools.md contain numerous commands such as otool, binwalk, checksec, readelf, and upx integrated into the workflow guides.
  • [DYNAMIC_EXECUTION]: The skill outlines workflows that involve runtime code generation, transpilation, and compilation for analysis purposes.
  • Evidence: references/tools.md describes converting WASM to C and then compiling it with gcc. references/patterns.md suggests using gcc to build optimized solvers for cryptographic challenges.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — reverse-ctf