steganography-techniques

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download external software from non-whitelisted sources, including Stegsolve.jar from caesum.com via HTTP and the stegseek binary from a GitHub user repository (RickdeJager/stegseek).
  • [COMMAND_EXECUTION]: The skill utilizes multiple package managers to install tools, including apt, pip3, gem, and go. It also provides commands for executing numerous forensic tools such as zsteg, steghide, binwalk, foremost, and multimon-ng on user-provided data.
  • [DYNAMIC_EXECUTION]: Several sections in SKILL.md contain inline Python code executed via python3 -c to perform tasks like PNG CRC brute-forcing, WAV header analysis, and Unicode character analysis. This allows for runtime logic execution based on processed file data.
  • [PRIVILEGE_ESCALATION]: The skill uses sudo commands for package installation (sudo apt install) and binary installation (sudo dpkg -i), which requires elevated permissions on the host system.
  • [INDIRECT_PROMPT_INJECTION]: Mandatory Evidence Chain:
  • Ingestion points: The skill is designed to process external, potentially untrusted files including images (PNG, JPEG, GIF), audio (WAV), and text documents as described in SKILL.md and STEGO_TOOLS_GUIDE.md.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded content within processed data are present.
  • Capability inventory: The skill possesses extensive capabilities including file system access, network downloads, and command execution through various forensic utilities and inline Python scripts.
  • Sanitization: The instructions do not specify any sanitization or validation of the external files or their metadata before they are processed by the forensic tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:14 PM
Security Audit — agent-trust-hub — steganography-techniques