pentest-report
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data (vulnerability descriptions, PoC steps, and evidence) to generate reports without implementing boundary markers or sanitization, creating a surface for indirect prompt injection.
- Ingestion points: In
SKILL.md, Step 1 instructions define the collection of external information including 'vulnerability list', 'detailed information', and 'PoC'. - Boundary markers: Absent. There are no instructions to the agent to use delimiters or to disregard instructions embedded within the provided vulnerability data.
- Capability inventory: The skill possesses file-system write capabilities, as documented in
SKILL.md(Step 6), where it saves output to a specific local directory. - Sanitization: Absent. The workflow lacks any validation or escaping mechanisms for the data provided by the user before it is interpolated into the final markdown document.
- [METADATA_POISONING]: The skill hardcodes absolute file system paths that reveal local environment details, specifically a local username.
- Evidence:
SKILL.mdreferences absolute paths/Users/huimingliao/Documents/code/pentest-skills/reports/and/Users/huimingliao/Documents/code/pentest-skills/templates/pentest_report_template.md, exposing the username 'huimingliao' and the host's directory structure.
Audit Metadata