ctf-solver
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data (challenge descriptions, source code, and network endpoints) to drive automated exploitation tasks. This creates a surface where a malicious challenge could contain instructions that compromise the agent's host environment.
- Ingestion points: User-provided challenge name, description, source code, and environment endpoints defined in
SKILL.md. - Boundary markers: Absent. The instructions do not establish clear boundaries or provide warnings to the agent to ignore instructions embedded within the challenge data.
- Capability inventory: The agent is empowered to execute Python scripts using
requestsandsocket, perform network operations viacurl, and read sensitive files (such as/flag,.env, and environment variables) to 'capture flags'. - Sanitization: Absent. There are no guidelines for validating or sanitizing user-provided source code or descriptions before the agent analyzes or interacts with them.
- [COMMAND_EXECUTION]: The skill explicitly directs the agent to generate and run standalone Python scripts and shell commands (
curl,cat,head,tail) to test and execute exploits. If the agent's logic is subverted via prompt injection, these capabilities could be used to attack the local host or internal network.
Audit Metadata