ctf-reverse

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for the agent to install the GEF (GDB Enhanced Features) tool using a piped shell execution pattern: bash -c "$(curl -fsSL https://gef.blah.cat/sh)" in the file tools-advanced-2.md.
  • [EXTERNAL_DOWNLOADS]: The skill references multiple external tools and repositories for installation, including:
  • https://github.com/zrax/pycdc in SKILL.md.
  • https://github.com/Lil-House/Pyarmor-Static-Unpack-1shot in languages.md.
  • https://github.com/ohos-decompiler/abc-decompiler in languages.md.
  • https://github.com/pwndbg/pwndbg in SKILL.md.
  • https://github.com/mandiant/GoReSym in languages-compiled.md.
  • [COMMAND_EXECUTION]: The skill extensively uses shell commands for tool installation and binary analysis, including pip install, apt install, git clone, chmod +x, and various debuggers/analyzers like gdb, radare2, and frida.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it is designed to ingest and process untrusted data from CTF challenges.
  • Ingestion points: The agent is instructed to read and analyze arbitrary binary files (binary), APK files (app.apk), and WASM modules (checker.wasm) as referenced in SKILL.md, tools.md, and platforms.md.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings when processing the contents of analyzed files.
  • Capability inventory: The skill allows access to Bash, Read, Write, Edit, WebFetch, and WebSearch tools as defined in the YAML frontmatter of SKILL.md.
  • Sanitization: Absent. There are no instructions to sanitize or validate the content extracted from target binaries before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 05:39 AM
Security Audit — agent-trust-hub — ctf-reverse