x64dbg
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for analyzing untrusted binaries, which introduces a potential indirect prompt injection surface if the agent interprets debugger output containing strings or symbols from the malware.
- Ingestion points: Target executables loaded for analysis as described in SKILL.md and references/unpacking-guide.md.
- Boundary markers: The skill does not define specific delimiters for separating tool output from instructions.
- Capability inventory: The skill utilizes x64dbg command execution, plugin functionality, and Python automation.
- Sanitization: No explicit sanitization of debuggee data is mentioned.
- [EXTERNAL_DOWNLOADS]: The skill contains instructions for the user to download x64dbg and several associated security plugins from official websites and GitHub repositories.
- Evidence: Download links for tools such as ScyllaHide, xAnalyzer, and SwissArmyKnife are provided in references/plugin-setup.md.
- [SAFE]: No malicious patterns, persistence mechanisms, or obfuscation were found. The skill is a legitimate resource for security analysis.
Audit Metadata