offensive-web-role

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to process and analyze untrusted external data from target web applications, which serves as a potential vector for indirect prompt injection attacks.
  • Ingestion points: The agent is instructed to read and map applications using robots.txt, sitemaps, JavaScript source maps, and API specifications (e.g., swagger.json).
  • Boundary markers: Absent. The instructions do not provide delimiters or specific warnings to ignore instructions that might be embedded within the processed web data.
  • Capability inventory: The skill explicitly mentions using curl and python scripts for request replays and identifies capabilities such as extracting credentials or securing reverse shells for handoff.
  • Sanitization: Absent. There is no guidance on sanitizing, escaping, or validating the content retrieved from external sources before the agent processes it for decision-making.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — offensive-web-role