nosql-injection

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides command-line instructions for utilizing external security assessment tools such as nosqlmap and nosqli.\n- [DATA_EXFILTRATION]: Includes Python code templates that perform network requests to interact with and extract data from target systems.\n- [DATA_EXFILTRATION]: Directs the agent to maintain an engagement log and save significant output to the local ./engagement/evidence/ directory.\n- [PROMPT_INJECTION]: Identifies a potential indirect prompt injection surface through the ingestion of untrusted target data.\n
  • Ingestion points: Data from target URLs and API parameters enters the agent's context during the testing process.\n
  • Boundary markers: No delimiters are specified to isolate untrusted data from the agent's instructions.\n
  • Capability inventory: The skill utilizes network request capabilities and filesystem write access.\n
  • Sanitization: No validation or sanitization of data retrieved from external targets is implemented in the provided scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 09:36 PM
Security Audit — agent-trust-hub — nosql-injection