ddos-guardian
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted AWS WAF configuration data provided as JSON files, which represents an indirect prompt injection surface if the agent obeys instructions embedded within rule names or statements.
- Ingestion points: The
waf-assess.pyscript reads and normalizes user-provided JSON files containing WAF rule names, statements, and metadata. - Boundary markers: The instructions do not define specific delimiters for the untrusted data, although they encourage the agent to verify the machine's findings against the configuration.
- Capability inventory: The skill uses
file_readandfile_writepermissions to process artifacts and generate the final HTML report. - Sanitization: The
waf-report.pyscript applies robust HTML escaping and sanitization to all content before rendering it into the final assessment report, mitigating cross-site scripting risks in the generated document.
Audit Metadata