skills/aeondave/malskill/openvas/Gen Agent Trust Hub

openvas

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the official Greenbone Community Edition Docker Compose configuration from a well-known service domain (greenbone.github.io).\n- [COMMAND_EXECUTION]: Provides instructions for installing the gvm-tools package via pip and executing docker-compose commands to manage the scanning environment.\n- [CREDENTIALS_UNSAFE]: Uses documented default administrative credentials ('admin'/'admin') for the service in configuration aliases, shell examples, and automation scripts.\n- [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to ingest and process vulnerability reports that aggregate data from external hosts.\n
  • Ingestion points: Scan results retrieved in XML, CSV, and PDF formats as described in SKILL.md and scan-configs.md.\n
  • Boundary markers: No specific boundary markers or instructions to ignore embedded content are provided in the skill.\n
  • Capability inventory: Utilizes gvm-cli and gvm-pyshell for scan task management and report generation.\n
  • Sanitization: The skill relies on the target software (OpenVAS) to handle and sanitize data from scanned hosts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — openvas