skills/aeondave/malskill/zsteg/Gen Agent Trust Hub

zsteg

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFENO_CODECOMMAND_EXECUTION
Full Analysis
  • [NO_CODE]: The skill consists entirely of a markdown file providing documentation and usage examples. No scripts, binaries, or configuration files are included in the skill package.
  • [COMMAND_EXECUTION]: The instructions describe running shell commands like zsteg, file, and strings. These are standard command-line tools for security analysis and are presented as manual workflows for the agent to follow.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of image files. This represents an attack surface where an adversary could embed malicious instructions in an image's bit-planes to influence the agent when it reads the tool's output.
  • Ingestion points: Analysis of PNG/BMP files via zsteg (SKILL.md).
  • Boundary markers: Absent. The instructions do not specify using delimiters or provide warnings for the agent to ignore instructions found within analyzed image data.
  • Capability inventory: The agent is instructed to use zsteg, file, strings, foremost, steghide, and stegseek (SKILL.md).
  • Sanitization: No sanitization or validation of the extracted data is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 12:33 PM
Security Audit — agent-trust-hub — zsteg