ot-security-assessment

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads vulnerability information and security advisories from established authorities including NIST (nvd.nist.gov), CISA (cisa.gov), and MITRE (cve.mitre.org).\n- [EXTERNAL_DOWNLOADS]: It provides instructions to download the dnp3-info.nse script from the official Nmap project community repository on GitHub.\n- [COMMAND_EXECUTION]: The skill utilizes standard tools such as nmap for network scanning, msfconsole for exploitation research, and python-based libraries for industrial protocol interaction.\n- [REMOTE_CODE_EXECUTION]: The download of the dnp3-info.nse script for use with Nmap constitutes remote code fetching, as these scripts are executable by the Nmap engine. The source is a well-known project repository.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting and processing data from external vulnerability databases which is then presented to the agent.\n
  • Ingestion points: JSON and HTML files from NIST and CISA (SKILL.md).\n
  • Boundary markers: Absent.\n
  • Capability inventory: Subprocess execution of nmap, msfconsole, and python3 (SKILL.md).\n
  • Sanitization: Not specified in the instruction logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 11:00 AM
Security Audit — agent-trust-hub — ot-security-assessment