cli-anything-lldb

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, untrusted sources (process memory, local variables, thread backtraces) which could contain malicious instructions designed to influence the agent.
  • Ingestion points: Commands such as memory read, memory find, frame locals, and expr in SKILL.md bring data from a debugged process into the agent context.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat debugged data as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill allows for process management, file loading (core load), and arbitrary expression evaluation through LLDB (SKILL.md).
  • Sanitization: There is no documented mechanism for sanitizing or filtering data retrieved from process memory before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill provides a set of commands that interact directly with the host system's processes, allowing the agent to launch, attach to, and control arbitrary executables via LLDB.
  • [DYNAMIC_EXECUTION]: The skill uses the expr command to evaluate expressions within the debugged process's context, which involves runtime evaluation of code snippets via the LLDB Python API.
  • [EXTERNAL_DOWNLOADS]: The skill instructions include a command to install the cli-anything-lldb package, which is a resource associated with the vendor 'hkuds'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:21 PM
Security Audit — agent-trust-hub — cli-anything-lldb