skills/aeondave/malskill/sstimap/Gen Agent Trust Hub

sstimap

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to clone the SSTImap repository from GitHub (https://github.com/vladko312/SSTImap). This is documented as a well-known security tool for lab and authorized testing environments.
  • [COMMAND_EXECUTION]: The documentation includes example commands for running the tool, such as python3 sstimap.py -u "http://target.com/render?name=*". These are instructional examples for the intended use of the security testing tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied target URLs and data, but the attack surface is limited to local command execution by the user for security auditing purposes.
  • Ingestion points: Target URLs and POST data markers (*) provided by the user in SKILL.md.
  • Boundary markers: None explicitly present in the instructional text.
  • Capability inventory: Executes local Python scripts (sstimap.py) via the shell as described in SKILL.md.
  • Sanitization: Standard command-line argument passing is used; the skill acts as a wrapper/guide for the external tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — sstimap