deobf-string

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill implements binary code emulation using the Unicorn Engine. It reads arbitrary bytes from a user-provided binary file and executes them within an emulated ARM64 environment to recover encrypted strings.
  • [COMMAND_EXECUTION]: The skill involves file system operations, including reading from user-specified binary paths and writing modified data to new '.patched' files. It also generates functional Python decryption scripts based on analyzed patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of binary files and code snippets, which serves as an attack surface for instructions targeting the agent.
  • Ingestion points: Binary files loaded from the filesystem and code snippets provided in the chat context.
  • Boundary markers: No specific delimiters or instructions are provided to the agent to ignore potential instructions embedded within the data being analyzed.
  • Capability inventory: The skill possesses the ability to read and write files, generate and potentially execute Python code, and perform CPU emulation of binary data.
  • Sanitization: There is no evidence of sanitization or validation logic for the input binaries or code snippets before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 05:57 PM