Network Security
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a large library of commands for system administration, service setup, and network testing. It include instructions for configuring lab services, such as a
chmod 777command inreferences/network-fundamentals.mdused to establish a public Samba share. While this provides broad permissions, it is appropriately contextualized for testing guest access in an isolated laboratory environment. - [EXTERNAL_DOWNLOADS]: The skill references the installation of common security utilities from established public registries, including the Shodan library from PyPI and various protocol auditors and scanners from official operating system package repositories. It also includes instructions for running the OWASP ZAP scanner via its official Docker image.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and analyze untrusted data from network scanning tools and protocol banners.
- Ingestion points: Service banners captured by Nmap, DNS TXT records, and search results retrieved from the Shodan API.
- Boundary markers: Absent; the instructions do not define specific delimiters or guidelines for the agent to distinguish tool output from its internal instructions.
- Capability inventory: The skill utilizes subprocess execution for multiple command-line network tools and performs file system operations for log analysis.
- Sanitization: Absent; the skill does not mention validation or sanitization of content returned by network services or scanning tools.
Audit Metadata