red-team-ops

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Fetches installation configuration from the official Metasploit repository on GitHub in references/metasploit.md. Following the download, the script is marked as executable and run locally.
  • [COMMAND_EXECUTION]: Provides numerous shell commands and a bash script for automating reconnaissance, vulnerability scanning, and exploitation tasks using tools like Amass, Nuclei, and Metasploit.
  • [EXTERNAL_DOWNLOADS]: References and utilizes various third-party security tools for reconnaissance and vulnerability discovery, such as Subfinder, Httpx, and Dalfox.
  • [PROMPT_INJECTION]: The skill documents procedures for ingesting and processing untrusted data during reconnaissance phases in references/tools.md. Ingestion points include target domain inputs and historical URL data. The capability inventory includes numerous shell commands and tool executions. No explicit sanitization or boundary markers are described in the processing logic, establishing a surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:20 PM
Security Audit — agent-trust-hub — red-team-ops