skills/aeondave/malskill/testssl/Gen Agent Trust Hub

testssl

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines workflows that involve the ingestion and analysis of data from untrusted external sources, such as TLS/SSL responses and certificate metadata from remote hosts, which could serve as a vector for malicious instructions targeting the agent context.\n
  • Ingestion points: Network protocol responses and certificate details parsed by testssl.sh and openssl (SKILL.md).\n
  • Capability inventory: Shell command execution for security scanning (testssl.sh, openssl), data parsing (jq), and file system interaction for report generation (SKILL.md, references/tls-hardening.md).\n
  • Boundary markers: Explicit delimiters or instructions to ignore potential injection in scan results are absent.\n
  • Sanitization: No sanitization or filtering logic is described for the content extracted from external targets.\n- [COMMAND_EXECUTION]: The skill relies on and provides examples for executing several system-level command-line tools, including testssl.sh, openssl, and jq, to perform network auditing and process JSON-formatted security findings.\n- [NO_CODE]: The skill is composed strictly of markdown documentation and does not contain any Python, JavaScript, or shell script files for the agent to execute.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — testssl