reverse-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading and installing well-known security tools and Model Context Protocol (MCP) servers from official sources, such as GhidraMCP and ida-pro-mcp, which are trusted community resources.
  • [COMMAND_EXECUTION]: The methodology includes executing standard system utilities, debuggers, and instrumentation tools (e.g., GDB, Frida, Radare2) for binary analysis, which is the intended core functionality of the skill.
  • [INDIRECT_PROMPT_INJECTION]: As a tool for analyzing untrusted code and binaries, the skill correctly acknowledges the risk of malicious data ingestion. It addresses this by explicitly instructing users to establish isolated analysis environments, such as virtual machines or containers, as documented in the malware analysis and firmware guides.
  • [SAFE]: The bundled tools, including an IDA Pro export plugin (ida_export_plugin.py) and an Android memory dumper (dex_memory_dumper.js), are legitimate utilities authored by the skill's vendor and contain no malicious code or obfuscated logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:19 PM
Security Audit — agent-trust-hub — reverse-engineering