satellite-ctf

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and parse untrusted data streams, such as radio captures, hex dumps, and responses from remote telecommand/telemetry services, as part of its core CTF-solving functionality.
  • Ingestion points: Data enters the agent's context through socket.recv() calls in the Python harness and via file ingestion of IQ/WAV recordings.
  • Capability inventory: The skill uses network sockets and subprocess calls to specialized SDR and orbital mechanics tools.
  • Sanitization: The harness uses specific regex patterns (e.g., rb"HTB\{[^}]+\}") to extract flags from untrusted payloads, focusing on protocol-specific parsing rather than generic content execution.
  • Assessment: This surface is an inherent requirement of the skill's purpose (CTF solving) and is considered safe within the context of an isolated lab environment.
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known and trusted third-party Python libraries and specialized tools required for aerospace security research.
  • Dependencies: References include spacepackets, ccsdspy, skyfield, sgp4, pyorbital, gr-satellites, and gps-sdr-sim.
  • Assessment: These are established tools from reputable sources in the SDR and satellite engineering communities.
  • [COMMAND_EXECUTION]: The skill provides Python code snippets for network communication and command-line examples for SDR tools (e.g., hackrf_transfer).
  • Evidence: Templates in ccsds-frame-construction.md and ground-systems-and-rf.md facilitate interaction with remote challenge endpoints.
  • Assessment: The commands are standard for technical security competitions and do not exhibit malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — satellite-ctf