eset-security-patch-tool-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions for using forensic tools such as
binwalk,radare2, andstringsto inspect binary files for malicious indicators. - [COMMAND_EXECUTION]: Includes Python code utilizing the
scapylibrary to sniff and analyze network traffic during software execution within a controlled environment. - [EXTERNAL_DOWNLOADS]: Fetches metadata and reporting endpoints from legitimate security software providers for authenticity verification.
- [EXTERNAL_DOWNLOADS]: Contains instructions to clone a repository for forensic analysis. This involves a target that the skill itself labels as malicious, though it provides specific safety guidance for the procedure.
- [PROMPT_INJECTION]: The skill ingests untrusted data from external URLs through the
requestslibrary to analyze landing pages. This creates an indirect ingestion surface where malicious instructions in HTML metadata or content could attempt to influence the agent. No boundary markers or sanitization logic are present for the processed data.
Audit Metadata