wireshark
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation includes a variety of shell command examples for utilizing
tshark,mergecap, andeditcapto perform network captures and analyze traffic files. - [INDIRECT_PROMPT_INJECTION]: The skill outlines workflows for interpreting data from external packet capture (
.pcap) files, which represents a potential ingestion surface for untrusted data. - Ingestion points: External network capture files processed through
tshark -ras described inSKILL.mdandreferences/pcap-forensics-workflows.md. - Boundary markers: Absent; the instructions do not specify delimiters or warnings for the content of the packets being analyzed.
- Capability inventory: The skill utilizes shell command execution for forensic tools and file system interaction.
- Sanitization: Absent; the agent relies on the packet parsing capabilities of the Wireshark suite.
Audit Metadata