ddos-guardian

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted AWS WAF configuration data provided as JSON files, which represents an indirect prompt injection surface if the agent obeys instructions embedded within rule names or statements.
  • Ingestion points: The waf-assess.py script reads and normalizes user-provided JSON files containing WAF rule names, statements, and metadata.
  • Boundary markers: The instructions do not define specific delimiters for the untrusted data, although they encourage the agent to verify the machine's findings against the configuration.
  • Capability inventory: The skill uses file_read and file_write permissions to process artifacts and generate the final HTML report.
  • Sanitization: The waf-report.py script applies robust HTML escaping and sanitization to all content before rendering it into the final assessment report, mitigating cross-site scripting risks in the generated document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:34 AM