cli-anything-lldb
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, untrusted sources (process memory, local variables, thread backtraces) which could contain malicious instructions designed to influence the agent.
- Ingestion points: Commands such as
memory read,memory find,frame locals, andexprinSKILL.mdbring data from a debugged process into the agent context. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat debugged data as untrusted or to ignore embedded instructions.
- Capability inventory: The skill allows for process management, file loading (
core load), and arbitrary expression evaluation through LLDB (SKILL.md). - Sanitization: There is no documented mechanism for sanitizing or filtering data retrieved from process memory before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill provides a set of commands that interact directly with the host system's processes, allowing the agent to launch, attach to, and control arbitrary executables via LLDB.
- [DYNAMIC_EXECUTION]: The skill uses the
exprcommand to evaluate expressions within the debugged process's context, which involves runtime evaluation of code snippets via the LLDB Python API. - [EXTERNAL_DOWNLOADS]: The skill instructions include a command to install the
cli-anything-lldbpackage, which is a resource associated with the vendor 'hkuds'.
Audit Metadata