testssl
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines workflows that involve the ingestion and analysis of data from untrusted external sources, such as TLS/SSL responses and certificate metadata from remote hosts, which could serve as a vector for malicious instructions targeting the agent context.\n
- Ingestion points: Network protocol responses and certificate details parsed by
testssl.shandopenssl(SKILL.md).\n - Capability inventory: Shell command execution for security scanning (
testssl.sh,openssl), data parsing (jq), and file system interaction for report generation (SKILL.md, references/tls-hardening.md).\n - Boundary markers: Explicit delimiters or instructions to ignore potential injection in scan results are absent.\n
- Sanitization: No sanitization or filtering logic is described for the content extracted from external targets.\n- [COMMAND_EXECUTION]: The skill relies on and provides examples for executing several system-level command-line tools, including
testssl.sh,openssl, andjq, to perform network auditing and process JSON-formatted security findings.\n- [NO_CODE]: The skill is composed strictly of markdown documentation and does not contain any Python, JavaScript, or shell script files for the agent to execute.
Audit Metadata