offensive-toctou

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous templates for shell commands and script snippets (C and Python) designed to automate the testing and reproduction of race conditions. These are clearly labeled as educational or exploitation research examples.
  • [EXTERNAL_DOWNLOADS]: Includes informational references to external resources, including the author's own GitHub repository (SnailSploit/offensive-checklist), MITRE CWE documentation, and PortSwigger research. These are documented neutrally as technical references.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing user-supplied data, such as paths and binary names, to generate strace commands and exploitation scripts. This ingestion of untrusted data is central to the skill's purpose as a vulnerability analysis tool and does not indicate malicious intent.
  • [SAFE]: No obfuscation, data exfiltration logic, privilege escalation outside of the documented TOCTOU research contexts, or persistence mechanisms were found. The skill operates consistently with its stated purpose of offensive security education.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:30 PM
Security Audit — agent-trust-hub — offensive-toctou