skills/trailofbits/skills/aflpp/Gen Agent Trust Hub

aflpp

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a shell wrapper script (./afl++) designed to execute fuzzer-related commands either on the host or inside a Docker container.
  • [PRIVILEGE_ESCALATION]: To achieve maximum fuzzing performance, the skill instructs the user to disable kernel security mitigations via afl-system-config and update-grub. It also utilizes the --privileged flag in its Docker execution wrapper to allow the fuzzer to interact with the host kernel.
  • [EXTERNAL_DOWNLOADS]: Fetches Docker images from Docker Hub (aflplusplus/aflplusplus) and source code/headers from the official AFL++ GitHub organization (github.com/AFLplusplus). These are well-known and reputable sources for this specific tooling.
  • [DYNAMIC_EXECUTION]: The generated wrapper script dynamically assembles shell commands from user-provided arguments and executes them inside a containerized environment using bash -c.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:08 AM
Security Audit — agent-trust-hub — aflpp