code-reverse-engineering-binary

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by instructing the agent to read and process output artifacts from binary analysis tools (e.g., findings.md, 01-static.md) that operate on untrusted target binaries. • Ingestion points: Artifact files in the /tmp/re-work/ session directory. • Boundary markers: None identified in the orchestration logic. • Capability inventory: Bash, Write, and Agent tools. • Sanitization: No specific sanitization or validation of the ingested tool output is mentioned.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool for filesystem operations and session management within the /tmp/re-work/ directory and uses the Agent tool to trigger specialized sub-agents for disassembly and instrumentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:02 AM
Security Audit — agent-trust-hub — code-reverse-engineering-binary