reverse-engineering

Fail

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading various reverse engineering tools from community-managed GitHub repositories that are not associated with trusted organizations, such as zrax/pycdc, worawit/blutter, and ohos-decompiler/abc-decompiler.\n- [REMOTE_CODE_EXECUTION]: The SKILL.md file contains instructions to clone the pycdc repository and build the software locally using cmake and make, which executes code from a third-party source.\n- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform complex environment setups and execute a wide variety of security tools including GDB, Radare2, and Frida.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection risk because it involves the ingestion and interpretation of untrusted data (binaries, firmware, and assets). Malicious content within these files could be used to influence the agent's actions during the analysis process, especially given the lack of explicit boundary markers or sanitization logic.\n- [SAFE]: The inclusion of resources such as loldrivers.io and the documentation of phishing infrastructure are provided solely for security analysis and educational purposes within the intended context of the skill.
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 17, 2026, 09:26 AM
Security Audit — agent-trust-hub — reverse-engineering