offensive-zigbee-thread-matter
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download security toolkits from GitHub repositories, specifically
IoTsec/Z3secandriverloopsec/killerbee. - [COMMAND_EXECUTION]: Instructions include several shell commands for network discovery (
zbstumbler), packet capturing (zbdump), and executing Python-based attack scripts from cloned repositories. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources during network sniffing and frame analysis operations.
- Ingestion points: Raw network frames ingested via hardware interfaces (e.g.,
/dev/ttyACM0) and processed byscapyorKillerBeetools. - Boundary markers: None identified in the instructional content.
- Capability inventory: File system access, network interface interaction, and arbitrary shell command execution.
- Sanitization: No specific sanitization or filtering is described for the data captured from mesh network protocols.
Audit Metadata