skills/aeondave/malskill/tcpdump/Gen Agent Trust Hub

tcpdump

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous commands for network packet capture, traffic filtering, and payload extraction using utilities like tcpdump, tshark, tcpflow, and ngrep.
  • [PRIVILEGE_ESCALATION]: The instructions include the use of sudo to acquire the necessary permissions for live network interface capture, which is standard procedure for the tcpdump utility.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external packet capture files (PCAPs). If an agent processes a PCAP containing malicious payloads or embedded instructions from an untrusted source, it could lead to indirect prompt injection.
  • Ingestion points: Network interfaces and PCAP files (references in SKILL.md and references/forensic-capture-flow.md).
  • Boundary markers: None present in the instructions to handle or ignore embedded data.
  • Capability inventory: Subprocess execution for network utilities (tcpdump, tshark), file read/write operations for PCAP management.
  • Sanitization: No specific sanitization or validation of packet payloads is described beyond standard utility filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — tcpdump