eset-security-patch-tool-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Provides instructions for using forensic tools such as binwalk, radare2, and strings to inspect binary files for malicious indicators.
  • [COMMAND_EXECUTION]: Includes Python code utilizing the scapy library to sniff and analyze network traffic during software execution within a controlled environment.
  • [EXTERNAL_DOWNLOADS]: Fetches metadata and reporting endpoints from legitimate security software providers for authenticity verification.
  • [EXTERNAL_DOWNLOADS]: Contains instructions to clone a repository for forensic analysis. This involves a target that the skill itself labels as malicious, though it provides specific safety guidance for the procedure.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external URLs through the requests library to analyze landing pages. This creates an indirect ingestion surface where malicious instructions in HTML metadata or content could attempt to influence the agent. No boundary markers or sanitization logic are present for the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 06:53 PM
Security Audit — agent-trust-hub — eset-security-patch-tool-analysis