attacking-bluetooth-nfc
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill is consistent with its stated purpose of providing educational and professional penetration testing instructions.
- [COMMAND_EXECUTION]: The skill makes extensive use of command-line tools for hardware interaction. All commands are standard for Bluetooth and NFC security research and do not include dangerous or unauthorized system modifications.
- [PROMPT_INJECTION]: The skill lacks any adversarial prompt injection patterns. It includes clear guidelines on scoping and legal authorization, which help prevent misuse of the instructions.
- [DATA_EXFILTRATION]: There are no patterns suggesting unauthorized data transfer. The skill focuses on capturing radio data for local analysis by the security professional.
- [PROMPT_INJECTION]: The skill provides the ability to ingest data from external radio sources (BLE and NFC), which is a potential surface for indirect prompt injection. However, this is a necessary part of the security analysis workflow and does not pose a direct threat to the agent's integrity in this context. 1. Ingestion points: BLE GATT characteristic reads (SKILL.md) and NFC tag dumps (SKILL.md). 2. Boundary markers: N/A. 3. Capability inventory: Radio hardware interaction commands (hcitool, gatttool, proxmark3) and local file writing. 4. Sanitization: Content is intended for researcher review.
Audit Metadata