pentest
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a Bash script
raw_http_vuln_verify.shthat usescurlto replay and verify HTTP-based vulnerabilities like open redirects and reflected XSS. This is a core function for the skill's stated purpose of offensive security validation. - [DATA_EXFILTRATION]: The skill provides detailed workflows in
references/secrets-exposure-workflows.mdfor discovering and validating the exposure of sensitive files and credentials (e.g.,.envfiles, AWS keys) within authorized targets. - [EXTERNAL_DOWNLOADS]: The documentation in
references/pentesting-shannon.mdreferences the use ofnpx @keygraph/shannon, which facilitates the download and execution of an external autonomous penetration testing framework. - [PROMPT_INJECTION]: The skill instructions in
SKILL.mdand related reference files use strong instructional language to define the agent's behavior, authorization requirements, and operational scope during pentesting tasks.
Audit Metadata