ctf-pwn

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, such as binary metadata, strings, and decompiled code, creating a potential surface for indirect prompt injection attacks where malicious instructions are hidden within the analyzed data.
  • Ingestion points: Data enters the context through analysis tools like get-strings, get-symbols, and get-decompilation as outlined in Phase 1 and Phase 2 of the workflow.
  • Boundary markers: The instructions lack specific boundary markers or "ignore" directives to prevent the agent from accidentally executing instructions found within the data it analyzes.
  • Capability inventory: The skill utilizes tools to modify the analysis environment, including rename-variables, set-decompilation-comment, set-bookmark, and checkin-program.
  • Sanitization: No sanitization or validation of the input data from the binary analysis tools is specified.
  • [NO_CODE]: The skill consists entirely of markdown instruction files and does not include any accompanying scripts, executables, or package dependency files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:25 PM