offensive-iot
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a high-level testing methodology for security researchers. While it contains commands for firmware extraction and device exploitation, these are clearly documented as instructions for the user to perform on target hardware during a penetration test.
- [COMMAND_EXECUTION]: The document lists various command-line tools (e.g., flashrom, binwalk, gatttool, bettercap, mosquitto_sub) for security analysis. These are standard industry tools for the described use case and are not executed by the skill itself.
- [CREDENTIALS_SAFE]: The skill mentions common default credentials (e.g., admin/admin, root/root) and a public Zigbee transport key (0x9F559A553B7A6B2C) used for testing. These are well-known educational examples and do not constitute a leak of sensitive credentials from the skill or environment.
- [INDIRECT_PROMPT_INJECTION]: As a methodology for processing external data (firmware images, radio traffic), the skill inherently describes a workflow involving untrusted inputs. However, this is part of the intended primary purpose (security testing) and the skill does not contain logic to automatically process these inputs without user supervision.
Audit Metadata