zap
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes numerous commands for running OWASP ZAP scanning scripts (e.g.,
zap-baseline.py,zap-full-scan.py) via Docker and local shell scripts. These commands are intended for automated security testing. - [INDIRECT_PROMPT_INJECTION]: The skill describes workflows where the agent reads and processes scan results and alerts from external web applications. This presents a potential surface for indirect prompt injection if an attacker controls the scanned target.
- Ingestion points: Vulnerability data is ingested via the Python client
zap.core.alerts(references/automation-api.md) and through reports generated by the scanning scripts (SKILL.md). - Boundary markers: No explicit delimitation or 'ignore instructions' markers are present in the examples.
- Capability inventory: The skill uses shell execution for Docker containers and
curlcommands (SKILL.md, references/automation-api.md). - Sanitization: The provided code snippets do not demonstrate sanitization or validation of the external scan data.
- [EXTERNAL_DOWNLOADS]: The skill references official
zaproxyresources, including Docker images (zaproxy/zap-stable) and the Python client library (zaproxy). These are well-known and authoritative security tools.
Audit Metadata