reverse-engineer
Warn
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes external binaries and CLI tools to extract metadata and help documentation.
- Evidence:
scripts/binary/capture_cli_help.shexecutes the target binary with the--helpflag usingrun_with_timeout "$@" --help. - Evidence:
scripts/reverse_engineer.pyusessubprocess.runto execute various tools includinggit,python3, andbashscripts. - [DYNAMIC_EXECUTION]: The skill generates and executes Python scripts during its operation.
- Evidence:
scripts/reverse_engineer.pycontains a hardcoded template in_write_wrapper_validate_feature_registrywhich it writes tovalidate-feature-registry.pyand subsequently executes viasubprocess.run. - Evidence:
scripts/binary/analyze_binary.shuses a heredoc to pass an embedded Python script topython3to scan for ZIP signatures within binary files. - [EXTERNAL_DOWNLOADS]: The skill fetches content from external sources which may include untrusted code or documentation.
- Evidence:
scripts/fetch_url.pyusesurllib.request.urlopento download sitemaps from user-provided URLs. - Evidence:
scripts/reverse_engineer.pyperformsgit cloneoperations on upstream repositories provided in the command arguments. - [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface as it ingests and processes data from external repositories, sitemaps, and binary artifacts.
- Ingestion points: Repository source files (e.g.,
package.json,go.mod), documentation files, sitemaps (sitemap.xml), and binary strings. - Boundary markers: The skill does not implement specific delimiters to separate untrusted repository content from the agent's instructions during analysis.
- Capability inventory: The skill possesses the ability to execute shell commands, run binaries, write to the filesystem, and perform network requests via
gitandurllib. - Sanitization: Includes
_ensure_real_directoryand_assert_no_symlinksinscripts/reverse_engineer.pyto prevent path traversal and symbolic link attacks in the output directory.
Audit Metadata