firmware-pentest
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill automates the installation of standard security tools (EMBA, Firmadyne, AFL++, binwalk, unblob) from well-known and reputable public repositories on GitHub.
- [SAFE]: Administrative privileges (sudo) are utilized exclusively for legitimate tasks necessary for firmware analysis, such as package installation, kernel module management (modprobe), and mounting extracted filesystems.
- [SAFE]: Network operations are limited to informational queries to well-known services (e.g., fccid.io) and the download of security tools and databases from official sources.
- [SAFE]: The skill manages the attack surface of indirect prompt injection by using diagnostic tools (strings, grep, binwalk) to process untrusted firmware data for inspection rather than direct execution.
- [SAFE]: All shellcode generation and exploitation examples are provided as educational templates for forensic and penetration testing use cases, with no evidence of self-targeting or malicious behavior.
Audit Metadata