protocol-reverse
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructional guidance for protocol analysis using standard industry tools such as tshark, Wireshark, and protoc.
- [COMMAND_EXECUTION]: The skill references a local initialization script (../scripts/case-init.ps1) and common command-line tools for traffic analysis. These are utilized within a defined workflow that emphasizes authorized scope and interaction.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data which may be untrusted. 1. Ingestion points: PCAP files, binary samples, and proxy logs are analyzed in Phase 1. 2. Boundary markers: The instructions lack explicit text delimiters but enforce operational boundaries through scope checks. 3. Capability inventory: Includes shell command execution (tshark, protoc), Python scripting, and local file reads. 4. Sanitization: No specific data sanitization logic is described, but the skill mandates evidence de-identification.
Audit Metadata