competition-reverse-pwn
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: All components of the skill, including the instructions and reference playbooks, are dedicated to legitimate security research and CTF competition workflows. No unauthorized command execution, data exfiltration, or obfuscation techniques were found.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data (binaries, PCAPs, memory dumps), which is an inherent risk for indirect prompt injection. However, this is consistent with the skill's stated purpose of malware analysis and forensics.
- Ingestion points: Artifacts, decoded layers, memory dumps, and packet captures specified in SKILL.md and references/reverse-pwn.md.
- Boundary markers: Absent; the instructions do not specify delimiters for data isolation.
- Capability inventory: No executable scripts or direct system calls are present in the skill files; behavior is limited to natural language instructions for the agent.
- Sanitization: Not present; the workflow relies on the user-provided sandbox environment.
Audit Metadata