analyze-elf

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute standard binary analysis utilities such as readelf, nm, and strings from the binutils package. These are used to inspect the structure of provided ELF binaries.
  • [COMMAND_EXECUTION]: The skill executes the binary being analyzed with the --help flag to extract CLI command structures. There is a 5-second timeout implemented to mitigate risks from interactive or long-running binaries.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with local services (localhost) for memory recall and LLM-based classification. It specifically targets http://127.0.0.1:8601 for a memory service and localhost:4001 for inference via scillm. These are internal platform dependencies rather than untrusted external URLs.
  • [COMMAND_EXECUTION]: The skill invokes other platform skills, such as treesitter and dogpile, via their run.sh entry points to perform AST analysis and documentation research respectively.
  • [DATA_EXFILTRATION]: While the skill communicates with internal services to store and recall analysis results, it does not show patterns of exfiltrating sensitive user credentials or private files to unauthorized external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — analyze-elf