reversing-technique
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted artifacts, such as malware samples, firmware images, and suspicious documents, which inherently creates an indirect prompt injection surface.
- Ingestion points: Multiple utility scripts (
triage.py,string_scanner.py,entropy_scan.py,iat_analyzer.py) take untrusted file paths as arguments for processing. - Boundary markers: The skill documentation (e.g.,
SKILL.md,references/dynamic-analysis.md) strongly emphasizes the use of isolated lab environments, virtual machine snapshots, and network simulation to mitigate risks associated with untrusted data. - Capability inventory: The skill possesses the capability to read and write files, execute shell commands, and interact with the network for tool installation.
- Sanitization: While the scripts parse raw binary data, the overarching methodology requires human-in-the-loop validation and execution within sandboxed environments.
- [COMMAND_EXECUTION]: The
setup_env.pyscript executes shell commands to facilitate the installation of necessary analysis tools. - Evidence: The script uses
subprocess.runwithshell=Trueto call system package managers such asapt-geton Linux andwingeton Windows. - Purpose: This behavior is strictly for environment preparation, ensuring that standard analysis tools like
gdb,yara, andbinwalkare available to the agent. - [EXTERNAL_DOWNLOADS]: The environment setup process involves downloading tools and libraries from external sources.
- Evidence:
setup_env.pyandreferences/install-guide.mdreference the retrieval of packages from official system repositories and well-known registries like PyPI and NPM. - Context: These downloads target established service providers and are essential for the skill's functionality.
Audit Metadata