sstimap
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to clone the SSTImap repository from GitHub (
https://github.com/vladko312/SSTImap). This is documented as a well-known security tool for lab and authorized testing environments. - [COMMAND_EXECUTION]: The documentation includes example commands for running the tool, such as
python3 sstimap.py -u "http://target.com/render?name=*". These are instructional examples for the intended use of the security testing tool. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied target URLs and data, but the attack surface is limited to local command execution by the user for security auditing purposes.
- Ingestion points: Target URLs and POST data markers (
*) provided by the user inSKILL.md. - Boundary markers: None explicitly present in the instructional text.
- Capability inventory: Executes local Python scripts (
sstimap.py) via the shell as described inSKILL.md. - Sanitization: Standard command-line argument passing is used; the skill acts as a wrapper/guide for the external tool.
Audit Metadata