pentest

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Bash script raw_http_vuln_verify.sh that uses curl to replay and verify HTTP-based vulnerabilities like open redirects and reflected XSS. This is a core function for the skill's stated purpose of offensive security validation.
  • [DATA_EXFILTRATION]: The skill provides detailed workflows in references/secrets-exposure-workflows.md for discovering and validating the exposure of sensitive files and credentials (e.g., .env files, AWS keys) within authorized targets.
  • [EXTERNAL_DOWNLOADS]: The documentation in references/pentesting-shannon.md references the use of npx @keygraph/shannon, which facilitates the download and execution of an external autonomous penetration testing framework.
  • [PROMPT_INJECTION]: The skill instructions in SKILL.md and related reference files use strong instructional language to define the agent's behavior, authorization requirements, and operational scope during pentesting tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 12:17 PM
Security Audit — agent-trust-hub — pentest