offensive-web-role
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to process and analyze untrusted external data from target web applications, which serves as a potential vector for indirect prompt injection attacks.
- Ingestion points: The agent is instructed to read and map applications using
robots.txt, sitemaps, JavaScript source maps, and API specifications (e.g.,swagger.json). - Boundary markers: Absent. The instructions do not provide delimiters or specific warnings to ignore instructions that might be embedded within the processed web data.
- Capability inventory: The skill explicitly mentions using
curlandpythonscripts for request replays and identifies capabilities such as extracting credentials or securing reverse shells for handoff. - Sanitization: Absent. There is no guidance on sanitizing, escaping, or validating the content retrieved from external sources before the agent processes it for decision-making.
Audit Metadata