reverse-engineering
Fail
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading various reverse engineering tools from community-managed GitHub repositories that are not associated with trusted organizations, such as
zrax/pycdc,worawit/blutter, andohos-decompiler/abc-decompiler.\n- [REMOTE_CODE_EXECUTION]: TheSKILL.mdfile contains instructions to clone thepycdcrepository and build the software locally usingcmakeandmake, which executes code from a third-party source.\n- [COMMAND_EXECUTION]: The skill utilizes theBashtool to perform complex environment setups and execute a wide variety of security tools including GDB, Radare2, and Frida.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection risk because it involves the ingestion and interpretation of untrusted data (binaries, firmware, and assets). Malicious content within these files could be used to influence the agent's actions during the analysis process, especially given the lack of explicit boundary markers or sanitization logic.\n- [SAFE]: The inclusion of resources such asloldrivers.ioand the documentation of phishing infrastructure are provided solely for security analysis and educational purposes within the intended context of the skill.
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata