openvas
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the official Greenbone Community Edition Docker Compose configuration from a well-known service domain (greenbone.github.io).\n- [COMMAND_EXECUTION]: Provides instructions for installing the gvm-tools package via pip and executing docker-compose commands to manage the scanning environment.\n- [CREDENTIALS_UNSAFE]: Uses documented default administrative credentials ('admin'/'admin') for the service in configuration aliases, shell examples, and automation scripts.\n- [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to ingest and process vulnerability reports that aggregate data from external hosts.\n
- Ingestion points: Scan results retrieved in XML, CSV, and PDF formats as described in SKILL.md and scan-configs.md.\n
- Boundary markers: No specific boundary markers or instructions to ignore embedded content are provided in the skill.\n
- Capability inventory: Utilizes gvm-cli and gvm-pyshell for scan task management and report generation.\n
- Sanitization: The skill relies on the target software (OpenVAS) to handle and sanitize data from scanned hosts.
Audit Metadata