decompression-bomb

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate instructional material and reference documentation for identifying resource exhaustion vulnerabilities in various programming languages (JavaScript, Python, Go).
  • [COMMAND_EXECUTION]: The file references/poc-skeleton.md contains a Python script template that uses the subprocess.run module to execute a local Node.js process. This is documented as a method for measuring memory growth and detecting OOM crashes in a controlled testing environment.
  • [EXTERNAL_DOWNLOADS]: No external network operations or unauthorized downloads were identified. All script templates use standard libraries or placeholders for user-specified packages.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 05:07 PM
Security Audit — agent-trust-hub — decompression-bomb