reverse-engineer

Warn

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes external binaries and CLI tools to extract metadata and help documentation.
  • Evidence: scripts/binary/capture_cli_help.sh executes the target binary with the --help flag using run_with_timeout "$@" --help.
  • Evidence: scripts/reverse_engineer.py uses subprocess.run to execute various tools including git, python3, and bash scripts.
  • [DYNAMIC_EXECUTION]: The skill generates and executes Python scripts during its operation.
  • Evidence: scripts/reverse_engineer.py contains a hardcoded template in _write_wrapper_validate_feature_registry which it writes to validate-feature-registry.py and subsequently executes via subprocess.run.
  • Evidence: scripts/binary/analyze_binary.sh uses a heredoc to pass an embedded Python script to python3 to scan for ZIP signatures within binary files.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from external sources which may include untrusted code or documentation.
  • Evidence: scripts/fetch_url.py uses urllib.request.urlopen to download sitemaps from user-provided URLs.
  • Evidence: scripts/reverse_engineer.py performs git clone operations on upstream repositories provided in the command arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface as it ingests and processes data from external repositories, sitemaps, and binary artifacts.
  • Ingestion points: Repository source files (e.g., package.json, go.mod), documentation files, sitemaps (sitemap.xml), and binary strings.
  • Boundary markers: The skill does not implement specific delimiters to separate untrusted repository content from the agent's instructions during analysis.
  • Capability inventory: The skill possesses the ability to execute shell commands, run binaries, write to the filesystem, and perform network requests via git and urllib.
  • Sanitization: Includes _ensure_real_directory and _assert_no_symlinks in scripts/reverse_engineer.py to prevent path traversal and symbolic link attacks in the output directory.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 4, 2026, 10:55 AM
Security Audit — agent-trust-hub — reverse-engineer