offensive-zigbee-thread-matter

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download security toolkits from GitHub repositories, specifically IoTsec/Z3sec and riverloopsec/killerbee.
  • [COMMAND_EXECUTION]: Instructions include several shell commands for network discovery (zbstumbler), packet capturing (zbdump), and executing Python-based attack scripts from cloned repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources during network sniffing and frame analysis operations.
  • Ingestion points: Raw network frames ingested via hardware interfaces (e.g., /dev/ttyACM0) and processed by scapy or KillerBee tools.
  • Boundary markers: None identified in the instructional content.
  • Capability inventory: File system access, network interface interaction, and arbitrary shell command execution.
  • Sanitization: No specific sanitization or filtering is described for the data captured from mesh network protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:32 PM
Security Audit — agent-trust-hub — offensive-zigbee-thread-matter