skills/adryanmoldokkr32-pixel/bionicbot-advanced-mechanics-security/automated-pentesting/Gen Agent Trust Hub
automated-pentesting
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run automated DAST tools (OWASP ZAP, Burp Suite) and simulate command injection attacks. These operations involve the generation and execution of potentially dangerous payloads and commands.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it requires the agent to ingest and analyze untrusted data from target applications and APIs, which could contain malicious instructions designed to subvert agent behavior.
- Ingestion points: Application content, API responses, and tool outputs retrieved during security scanning (SKILL.md).
- Boundary markers: Absent. There are no instructions to use delimiters or ignore instructions embedded within the data being analyzed.
- Capability inventory: Running security scanning tools and performing simulated injection attacks (SKILL.md).
- Sanitization: Absent. No validation or escaping of the target application's data is described before the agent processes it.
- [NO_CODE]: This skill provides only documentation and high-level instructions within a markdown file. It does not include any scripts, configuration files, or binaries.
Audit Metadata