seccomp-tools
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides commands for executing
seccomp-toolsto dump and analyze process filters. These are standard security research actions that involve interacting with binary execution and process identifiers. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and disassembly of binary BPF (Berkeley Packet Filter) data. This creates a surface where maliciously crafted filters or binary metadata could attempt to influence the agent's interpretation of the security policy.
- Ingestion points: Data enters the agent context through the output of
seccomp-tools dumpandseccomp-tools disasminSKILL.mdworkflows. - Boundary markers: The skill does not define specific delimiters or instructions to ignore potential commands embedded within disassembled BPF logic.
- Capability inventory: The skill utilizes shell command execution to run the
seccomp-toolssuite. - Sanitization: There is no evidence of sanitization or validation of the disassembled output before it is presented to the agent for analysis.
Audit Metadata