httpx
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
httpxutility and related tools likesubfinderanddnsxfor network probing tasks.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web servers, which is a potential vector for indirect prompt injection.\n - Ingestion points: The skill retrieves HTTP response data, including titles, body content, and headers from external hosts (SKILL.md).\n
- Boundary markers: There are no explicit delimiters or instructions provided to isolate or disregard potential instructions embedded within the untrusted response content.\n
- Capability inventory: The skill uses the tool to perform network requests, follow redirects, and write the findings to local files (SKILL.md).\n
- Sanitization: No specific methods for sanitizing or validating the content retrieved from remote web servers are defined in the instructions.\n- [NO_CODE]: The skill contains only markdown documentation and reference files (SKILL.md, references/output-fields.md) and does not provide executable scripts or configuration code.
Audit Metadata