vm-and-bytecode-reverse

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions and code templates for the agent to ingest and analyze untrusted external data, such as binary files and custom bytecode programs.
  • Ingestion points: The skill includes Python snippets for reading binary files (open('challenge', 'rb')) and processing data from tools like IDA Pro (idc.get_bytes) as described in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters provided to prevent the agent from being influenced by instructions that might be embedded within the bytecode or binary data being analyzed.
  • Capability inventory: The analysis workflow involves high-capability tools such as symbolic execution engines (angr), emulators (Unicorn), and custom Python scripts for data transformation, which increases the attack surface if the input data is malicious.
  • Sanitization: The provided code templates do not include validation or sanitization for the binary content being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:09 AM
Security Audit — agent-trust-hub — vm-and-bytecode-reverse