pentesting-checklist-interactive

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external GitHub repository (https://github.com/m14r41/PentestingChecklist.git) as the source for the tool's codebase. This is a standard reference for an open-source security tool.
  • [COMMAND_EXECUTION]: The documentation includes standard shell commands for the installation, development, and deployment of a React/TypeScript application using tools like npm, git, vercel, and netlify.
  • [INDIRECT_PROMPT_INJECTION]: The tool ingests external data through a JSON import feature and user-provided notes in the checklist items. While the skill includes code for validating the structure of imported JSON files, there are no explicit instructions or delimiters shown to prevent potentially malicious payloads in imported notes from influencing the agent's interpretation when summarizing or exporting findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 01:17 PM
Security Audit — agent-trust-hub — pentesting-checklist-interactive