pentest
Warn
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
clearwingpackage from the public PyPI registry usinguv tool install clearwing. Neither the tool nor the author (Lazarus-AI) are included in the trusted vendors list or recognized as a well-known service. - [COMMAND_EXECUTION]: The skill provides instructions to run various shell commands using the
clearwingCLI, includingsourcehuntfor scanning local codebases andparallelfor concurrent network scanning of target CIDR blocks. - [COMMAND_EXECUTION]: The skill presents an indirect prompt injection attack surface as it ingests untrusted source code repositories via the
sourcehuntcommand while possessing access to theBashtool; the instructions lack explicit boundary markers or sanitization guidelines for the processed content.
Audit Metadata