tcpdump
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous commands for network packet capture, traffic filtering, and payload extraction using utilities like tcpdump, tshark, tcpflow, and ngrep.
- [PRIVILEGE_ESCALATION]: The instructions include the use of sudo to acquire the necessary permissions for live network interface capture, which is standard procedure for the tcpdump utility.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external packet capture files (PCAPs). If an agent processes a PCAP containing malicious payloads or embedded instructions from an untrusted source, it could lead to indirect prompt injection.
- Ingestion points: Network interfaces and PCAP files (references in SKILL.md and references/forensic-capture-flow.md).
- Boundary markers: None present in the instructions to handle or ignore embedded data.
- Capability inventory: Subprocess execution for network utilities (tcpdump, tshark), file read/write operations for PCAP management.
- Sanitization: No specific sanitization or validation of packet payloads is described beyond standard utility filtering.
Audit Metadata