skills/aeondave/malskill/sparrow-wifi/Gen Agent Trust Hub

sparrow-wifi

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill clones code from an external GitHub repository (https://github.com/ghostop14/sparrow-wifi) and installs dependencies using pip.
  • [METADATA_POISONING]: The skill claims to be authored by 'AeonDave', but the installation instructions direct users to a repository owned by a different user, 'ghostop14'. This discrepancy suggests a potential impersonation or supply chain attack.
  • [PRIVILEGE_ESCALATION]: The provided commands require the use of sudo to execute the downloaded Python scripts. Running code from an unverified third-party source with administrative privileges is a high-risk activity.
  • [COMMAND_EXECUTION]: The skill performs shell-level operations, including cloning repositories and installing software packages, which are then executed with elevated permissions.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The tool processes external wireless data such as Wi-Fi SSIDs, Bluetooth device names, and spectrum information (SKILL.md, references/hackrf-bluetooth-agent-workflows.md).
  • Boundary markers: None identified. There are no instructions to the agent to treat data collected from the wireless environment as potentially malicious.
  • Capability inventory: The skill executes shell commands and runs Python scripts as root.
  • Sanitization: There is no evidence of sanitization or filtering for captured wireless metadata, which could be crafted to influence agent behavior.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — sparrow-wifi