nmap
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is a structured collection of Nmap commands and workflows designed for network discovery, port scanning, and service enumeration.
- [PRIVILEGE_ESCALATION]: The documentation explicitly identifies scan types that require administrative or root privileges to function, such as TCP SYN stealth scans (
-sS) and OS fingerprinting (-O). While this involves elevated permissions, it is documented as a standard requirement for the tool's operation. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by instructing the agent to process external data sources.
- Ingestion points: Network service banners, NSE script outputs, and local files (e.g.,
targets.txt,users.txt,passwords.txt). - Boundary markers: None identified in the provided documentation.
- Capability inventory: The skill facilitates extensive shell command execution through the Nmap binary.
- Sanitization: No specific sanitization or validation of the external network responses or file inputs is described.
Audit Metadata