skills/aeondave/malskill/spi-flash/Gen Agent Trust Hub

spi-flash

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates hardware interaction using standard open-source utilities (flashrom, binwalk, md5sum). All commands are used within their intended functional scope for reading, verifying, and writing SPI flash content.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data by analyzing firmware dumps (fw_dump1.bin) using binwalk. This represents a standard hardware analysis workflow rather than a malicious vector.
  • Ingestion points: Raw firmware binary files read from SPI flash chips (SKILL.md).
  • Boundary markers: Absent; data is processed as raw binary.
  • Capability inventory: Toolset includes flashrom (device I/O) and binwalk (static analysis).
  • Sanitization: None; the skill provides raw analysis of hardware-extracted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — spi-flash