ctf-reverse
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions for the agent to install the GEF (GDB Enhanced Features) tool using a piped shell execution pattern:
bash -c "$(curl -fsSL https://gef.blah.cat/sh)"in the filetools-advanced-2.md. - [EXTERNAL_DOWNLOADS]: The skill references multiple external tools and repositories for installation, including:
https://github.com/zrax/pycdcinSKILL.md.https://github.com/Lil-House/Pyarmor-Static-Unpack-1shotinlanguages.md.https://github.com/ohos-decompiler/abc-decompilerinlanguages.md.https://github.com/pwndbg/pwndbginSKILL.md.https://github.com/mandiant/GoReSyminlanguages-compiled.md.- [COMMAND_EXECUTION]: The skill extensively uses shell commands for tool installation and binary analysis, including
pip install,apt install,git clone,chmod +x, and various debuggers/analyzers likegdb,radare2, andfrida. - [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it is designed to ingest and process untrusted data from CTF challenges.
- Ingestion points: The agent is instructed to read and analyze arbitrary binary files (
binary), APK files (app.apk), and WASM modules (checker.wasm) as referenced inSKILL.md,tools.md, andplatforms.md. - Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings when processing the contents of analyzed files.
- Capability inventory: The skill allows access to
Bash,Read,Write,Edit,WebFetch, andWebSearchtools as defined in the YAML frontmatter ofSKILL.md. - Sanitization: Absent. There are no instructions to sanitize or validate the content extracted from target binaries before it is processed by the agent.
Audit Metadata