argus

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute multiple Python scripts from a local tools directory, including cors_scanner.py, crlf_scanner.py, nosqli_scanner.py, jwt_scanner.py, oob_listener.py, and llm_redteam.py. These scripts perform active network scanning and data manipulation.- [INDIRECT_PROMPT_INJECTION]: The suite is designed to ingest and analyze data from external targets, which could contain malicious payloads intended to influence the agent's behavior. * Ingestion points: External URLs, API responses, and chatbot outputs are processed by tools such as llm_redteam.py and cors_scanner.py. * Boundary markers: No explicit instructions are provided to the agent to treat target output as untrusted or to use delimiters. * Capability inventory: The skill uses Python for network requests and allows for file redirection (e.g., writing to inter.jsonl). * Sanitization: There is no mention of sanitizing or escaping the data received from external endpoints.- [DATA_EXFILTRATION]: The skill uses the interactsh service for out-of-band (OOB) confirmation. While used here for confirming vulnerabilities like SSRF or XXE, this mechanism establishes a remote channel that could be used to exfiltrate data from the execution environment to external servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 10:34 AM
Security Audit — agent-trust-hub — argus