anti-reversing-techniques
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted binary samples, which could potentially contain malicious instructions or data patterns targeting the analysis agent.\n
- Ingestion points: Processes a user-provided "Binary path or sample" as its primary input (SKILL.md).\n
- Capability inventory: The skill utilizes significant execution capabilities including CLI tools (
upx,gdb,gcc), Python script execution, and binary modification scripts for IDA Pro and x64dbg (references/details.md).\n - Boundary markers: While a legal/authorized use warning is present, there are no technical delimiters or specific instructions for the agent to ignore embedded content within the binary data.\n
- Sanitization: The skill lacks explicit sanitization or validation steps for the input binary before processing it with analysis tools.\n- [DYNAMIC_EXECUTION]: The skill provides several functional code snippets and templates for the agent to generate and use during analysis tasks.\n
- Evidence: Provides Python scripts for tasks such as restoring modified UPX headers, scanning for timing-based anti-debug patterns, and performing string decryption within IDA Pro (references/advanced-techniques.md, references/details.md).\n
- Evidence: Includes C code templates for implementing ptrace hooks and various anti-analysis checks (references/details.md).\n- [COMMAND_EXECUTION]: The skill's workflow involves executing powerful system-level CLI tools for binary manipulation.\n
- Evidence: Instructs the use of
upxfor decompression,gccfor compiling shared library hooks, andgdborx64dbgcommand sequences for bypassing runtime checks (references/advanced-techniques.md, references/details.md).\n- [EXTERNAL_DOWNLOADS]: The skill refers the user and agent to external third-party security platforms for obtaining analysis tools.\n - Evidence: Recommends fetching specialized unpacker tools from community platforms such as UnpacMe and MalwareBazaar (references/advanced-techniques.md).
Audit Metadata