stevens-network-protocols

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The main H1 title in SKILL.md contains a long sequence of hidden Unicode characters (U+200B, U+200C, U+200D, U+2060). This steganographic technique is used to embed data that is invisible to the user but can be interpreted by the AI agent or used to bypass security filters. The presence of such obfuscation in a skill's metadata is a significant security red flag.
  • [COMMAND_EXECUTION]: The code provided in the skill includes a capture_and_analyze function that utilizes raw sockets (socket.AF_PACKET, socket.SOCK_RAW). Executing this code requires administrative or root privileges on most systems and allows the agent to interact directly with the network interface, bypassing standard operating system network stack restrictions.
  • [DATA_EXFILTRATION]: By enabling raw packet sniffing, the skill provides a mechanism to monitor all network traffic on the host machine. This could allow an attacker or a compromised agent to capture sensitive data, including login credentials, session tokens, and private communications from other applications on the system.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process and analyze external, untrusted data (network packets).
  • Ingestion points: The skill reads raw bytes directly from the network interface using the sock.recvfrom method in the capture_and_analyze function in SKILL.md.
  • Boundary markers: There are no boundary markers or instructions to the agent to disregard potential commands embedded within the packet payloads during analysis.
  • Capability inventory: The skill combines the ability to read low-level network data with complex parsing logic for multiple protocols, providing a significant attack surface for instructions hidden within network traffic.
  • Sanitization: While the code includes basic ASCII/UTF-8 decoding with error handling, it does not sanitize the content for potential prompt injection attacks contained within the protocol payloads.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:06 PM