reverse-engineer-anything

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill directs the agent to execute npx -y rea-agents@latest doctor and setup for environment management. This results in the runtime download and execution of arbitrary code from the public NPM registry. The use of the @latest tag creates a supply chain risk, as any compromise of the package would be automatically executed in the user's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze untrusted external artifacts such as native binaries, Electron ASAR files, and browser runtime data. These ingestion points (analyze_javascript_application, open_binary, list_browser_targets) represent a broad attack surface where malicious strings within analyzed files could influence agent behavior. While the skill suggests distinguishing observations from inferences, it lacks explicit sanitization for extracted strings before they enter the prompt context.
  • [COMMAND_EXECUTION]: The skill utilizes powerful tools that could be abused if the agent is compromised. The extract_artifact tool writes files to the local filesystem, and run_controlled_replay tool executes JavaScript modules. While approval steps are mentioned, these capabilities provide an exploitation path for successful prompt injections.
  • [DATA_EXFILTRATION]: The skill can observe and list active browser targets and Electron runtimes. Although it claims to exclude credentials, the ability to inspect open sessions and capture screenshots represents a potential risk to user privacy and sensitive data exposure.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 08:37 AM
Security Audit — agent-trust-hub — reverse-engineer-anything