routeros-sniffer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of several CLI tools for networking and virtualization, including tshark, qemu-system-x86_64, curl, and scp to manage packet captures and interact with the RouterOS REST API.
  • [PRIVILEGE_ESCALATION]: Documentation in references/tzsp-receivers.md instructs the user to use sudo apt install tshark, which requires administrative privileges on the host system to install dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface where an agent could ingest untrusted data from network packets.
  • Ingestion points: Live output from tshark and the contents of downloaded .pcap files as described in SKILL.md and references/tzsp-receivers.md.
  • Boundary markers: None present; there are no instructions to the agent to treat packet data as untrusted or to ignore embedded commands.
  • Capability inventory: The skill utilizes shell execution for tshark, curl, and qemu commands.
  • Sanitization: No sanitization, validation, or filtering of the captured packet payload is specified before the agent processes the information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:14 PM
Security Audit — agent-trust-hub — routeros-sniffer