ctf-sandbox-orchestrator
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a documentation and routing framework for security challenges. It does not contain executable code, automated downloaders, or hidden instructions.- [SAFE]: Includes a comprehensive list of external resources in
references/ctf-resources-digest.md, including well-known security tools (e.g., Pwntools, Ghidra, CyberChef) and educational platforms (e.g., HackTheBox, CTFTime, TryHackMe). These are documented neutrally and align with the skill's stated purpose.- [SAFE]: Proactively addresses Indirect Prompt Injection risks in the 'Core Rules' section by instructing the agent to treat all challenge artifacts (prompts, logs, HTML, etc.) as untrusted data rather than instructions.
Audit Metadata