ctf-pwn
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install a variety of security-focused tools and libraries, including
pwntools,ROPgadget,ropper,one_gadget,seccomp-tools,gdb, andpwndbg. These are installed from established services such as PyPI, RubyGems, and GitHub. - [COMMAND_EXECUTION]: The skill provides numerous shell commands for binary analysis, debugging, and environment setup. The
Bashtool is used extensively to run diagnostic utilities (checksec,readelf) and to execute exploit scripts. - [INDIRECT_PROMPT_INJECTION]: The skill describes workflows for interacting with untrusted binary targets and network services, creating a potential surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through the output of target binaries (Bash tool), file reads during analysis (Read tool), and interactions with remote network services (WebFetch tool).
- Boundary markers: Instructions do not consistently advise the use of delimiters or 'ignore embedded instructions' warnings when parsing output from untrusted sources.
- Capability inventory: The skill uses the Bash, Read, Write, Edit, and WebFetch tools, allowing for arbitrary command execution and filesystem modifications.
- Sanitization: Payloads are often constructed by parsing raw bytes from target output (e.g., leaked memory addresses) without explicit sanitization beyond ensuring valid binary formats.
- [DYNAMIC_EXECUTION]: The skill includes Python templates in the
scripts/directory that dynamically generate shellcode and ROP (Return-Oriented Programming) chains based on runtime analysis of target binaries. - [PRIVILEGE_ESCALATION]: The documentation describes various techniques for achieving privilege escalation on target systems (e.g.,
kernel.mdfor kernel exploits andadvanced-exploits-4.mdfor Windows SYSTEM escalation). These are documented as techniques to be performed on targets, not actions performed by the skill itself on the host environment.
Audit Metadata