vuln-search-technique

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads vulnerability definitions and exploit intelligence from trusted and well-known sources including CISA's KEV catalog, NIST's National Vulnerability Database (NVD), and CVE.org. These external references are appropriate for the skill's purpose.
  • [COMMAND_EXECUTION]: Instructs the agent to execute standard security auditing tools such as nmap, nuclei, and nikto. These commands are correctly scoped to the objective of identifying service versions and misconfigurations on target assets.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external targets, including service banners and scanner logs. While this introduces a surface for indirect prompt injection from untrusted target content, the methodology emphasizes manual verification and triage to minimize risks.
  • [DYNAMIC_EXECUTION]: Employs a localized Python script to parse structured Nmap results. This use of dynamic code is limited to data processing and does not involve untrusted remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — vuln-search-technique