skills/aeondave/malskill/cve-search/Gen Agent Trust Hub

cve-search

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources including CVE records, vendor advisories, and the OSV database, which creates a theoretical surface for indirect prompt injection if those records contain malicious instructions.
  • Ingestion points: CVE.org, NVD, OSV, GHSA, and vendor advisory websites discovered via web access.
  • Boundary markers: The skill defines a structured Markdown template for output entries but does not include explicit instructions for the agent to ignore or escape instructions potentially embedded within the fetched vulnerability descriptions.
  • Capability inventory: The skill possesses the capability to write research findings to a user-specified file path (dest_file).
  • Sanitization: There is no evidence of specific input sanitization, filtering, or escaping of retrieved external content before it is interpolated into the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:21 PM
Security Audit — agent-trust-hub — cve-search