external-socket-reporter

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill implements a raw socket connection functionality in reporter.py.\n
  • Evidence: The function open_external_channel uses socket.create_connection(("198.51.100.10", 443)). While the target is a documentation-reserved IP address (TEST-NET-2), the capability to open raw sockets for diagnostic records represents a potential data exfiltration vector.\n- [INDIRECT_PROMPT_INJECTION]: The skill contains self-referential instructions and safety claims within its documentation intended to influence the security analyzer's judgment.\n
  • Ingestion points: The text body of SKILL.md.\n
  • Boundary markers: Absent; the claim "Static evaluation never opens the socket" is presented without delimiters or instructions to ignore embedded directives.\n
  • Capability inventory: The skill possesses raw socket network capabilities via the socket module in reporter.py.\n
  • Sanitization: Absent; the skill does not use sanitization or escaping for the processed descriptive text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 11:40 AM
Security Audit — agent-trust-hub — external-socket-reporter