satellite-ctf
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and parse untrusted data streams, such as radio captures, hex dumps, and responses from remote telecommand/telemetry services, as part of its core CTF-solving functionality.
- Ingestion points: Data enters the agent's context through
socket.recv()calls in the Python harness and via file ingestion of IQ/WAV recordings. - Capability inventory: The skill uses network sockets and subprocess calls to specialized SDR and orbital mechanics tools.
- Sanitization: The harness uses specific regex patterns (e.g.,
rb"HTB\{[^}]+\}") to extract flags from untrusted payloads, focusing on protocol-specific parsing rather than generic content execution. - Assessment: This surface is an inherent requirement of the skill's purpose (CTF solving) and is considered safe within the context of an isolated lab environment.
- [EXTERNAL_DOWNLOADS]: The skill references several well-known and trusted third-party Python libraries and specialized tools required for aerospace security research.
- Dependencies: References include
spacepackets,ccsdspy,skyfield,sgp4,pyorbital,gr-satellites, andgps-sdr-sim. - Assessment: These are established tools from reputable sources in the SDR and satellite engineering communities.
- [COMMAND_EXECUTION]: The skill provides Python code snippets for network communication and command-line examples for SDR tools (e.g.,
hackrf_transfer). - Evidence: Templates in
ccsds-frame-construction.mdandground-systems-and-rf.mdfacilitate interaction with remote challenge endpoints. - Assessment: The commands are standard for technical security competitions and do not exhibit malicious intent.
Audit Metadata