pentest-report

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data (vulnerability descriptions, PoC steps, and evidence) to generate reports without implementing boundary markers or sanitization, creating a surface for indirect prompt injection.
  • Ingestion points: In SKILL.md, Step 1 instructions define the collection of external information including 'vulnerability list', 'detailed information', and 'PoC'.
  • Boundary markers: Absent. There are no instructions to the agent to use delimiters or to disregard instructions embedded within the provided vulnerability data.
  • Capability inventory: The skill possesses file-system write capabilities, as documented in SKILL.md (Step 6), where it saves output to a specific local directory.
  • Sanitization: Absent. The workflow lacks any validation or escaping mechanisms for the data provided by the user before it is interpolated into the final markdown document.
  • [METADATA_POISONING]: The skill hardcodes absolute file system paths that reveal local environment details, specifically a local username.
  • Evidence: SKILL.md references absolute paths /Users/huimingliao/Documents/code/pentest-skills/reports/ and /Users/huimingliao/Documents/code/pentest-skills/templates/pentest_report_template.md, exposing the username 'huimingliao' and the host's directory structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:47 PM
Security Audit — agent-trust-hub — pentest-report