rop-development-dev
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill identifies a development workflow utilizing several command-line tools for binary analysis and exploitation, including
checksec,Ropper,ROPgadget,rabin2, and debuggers such asgdb,windbg, orx64dbg. These are standard tools in the cybersecurity industry for research and vulnerability assessment. - [INDIRECT_PROMPT_INJECTION]: The skill's core function involves processing external binary files and logs from gadget-discovery tools, which represents a potential attack surface for indirect prompt injection.
- Ingestion points: The agent reads binary protections and output from analysis tools (like Ropper or ROPgadget) to generate exploitation chains.
- Boundary markers: The skill does not explicitly instruct the agent to use delimiters or ignore embedded instructions when parsing external binary data or tool outputs.
- Capability inventory: The methodology requires the execution of multiple binary analysis and debugging tools via shell commands to survey targets and enumerate gadgets.
- Sanitization: No specific filtering or sanitization steps are defined for handling the external data ingested from analysis tools.
Audit Metadata