wireless-technique
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of
sudoto execute wireless auditing tools such asairmon-ng,airodump-ng,kismet,hcxdumptool, andhostapd. This is a necessary and standard practice for tasks requiring monitor mode, raw packet injection, and low-level hardware control on Linux systems. - [EXTERNAL_DOWNLOADS]: Instructions include downloading the
eaphammertool from a third-party GitHub repository (github.com/s0lst1c3/eaphammer) and installing its requirements viapip. This is standard for deploying specialized security tooling not found in default package registries. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it processes untrusted data from the environment.
- Ingestion points: Reads wireless traffic (PCAP/pcapng), device survey results (CSV), and user input from captive portal forms.
- Boundary markers: The instructions lack specific delimiters or warnings for the agent to ignore potentially malicious instructions embedded within captured network data.
- Capability inventory: The skill has access to administrative shell execution (sudo) and file system write operations.
- Sanitization: There is no mention of sanitizing or escaping the content of captured packets or portal responses before processing.
Audit Metadata