competition-linux-credential-pivot

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No malicious code, obfuscation, or suspicious instructions were detected across the skill files.
  • [DATA_EXPOSURE]: The skill directs the agent to identify and record sensitive artifacts such as SSH keys, cloud tokens, and service-account secrets. This is consistent with its stated purpose as a CTF analysis tool.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it analyzes untrusted system data. (1) Ingestion points: environment variables, config files, and process memory clues. (2) Boundary markers: No delimiters or warnings against embedded instructions are provided. (3) Capability inventory: No custom scripts are included; the skill relies on the agent's platform tools. (4) Sanitization: No sanitization or validation of ingested artifacts is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 09:26 AM
Security Audit — agent-trust-hub — competition-linux-credential-pivot