nosql-injection
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides command-line instructions for utilizing external security assessment tools such as nosqlmap and nosqli.\n- [DATA_EXFILTRATION]: Includes Python code templates that perform network requests to interact with and extract data from target systems.\n- [DATA_EXFILTRATION]: Directs the agent to maintain an engagement log and save significant output to the local ./engagement/evidence/ directory.\n- [PROMPT_INJECTION]: Identifies a potential indirect prompt injection surface through the ingestion of untrusted target data.\n
- Ingestion points: Data from target URLs and API parameters enters the agent's context during the testing process.\n
- Boundary markers: No delimiters are specified to isolate untrusted data from the agent's instructions.\n
- Capability inventory: The skill utilizes network request capabilities and filesystem write access.\n
- Sanitization: No validation or sanitization of data retrieved from external targets is implemented in the provided scripts.
Audit Metadata