results-storage
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The file
scripts/storage_api.pyis provided in a mangled, packed format where code is collapsed into a single block with unusual backslash escaping and redundant import statements. This style of code packing is commonly used to bypass simple text-based security scanners and significantly increases the effort required for manual code verification, violating the principle of transparency. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a repository for untrusted data, specifically penetration testing findings (e.g., XSS payloads, SQL injection proofs, and malicious web findings), which are then rendered into reports that the AI agent is intended to read and process.
- Ingestion points: Data enters the system via the
StorageAPIclass inscripts/storage_api.pyand the variousstore_*methods. - Boundary markers: Reports generated in
scripts/report_generator.pyuse standard Markdown headers and horizontal rules, but they lack explicit instructions or strict delimiters to ensure the agent ignores executable instructions found within the stored findings. - Capability inventory: The skill has the capability to query the local SQLite database and write content to local files (
.mdand.json). - Sanitization: There is no sanitization or escaping of the
proof_of_concept,payload, orresponse_evidencefields before they are written into Markdown or JSON reports. This allows raw, potentially malicious instructions stored during a scan to be presented back to the agent in a high-trust context.
Audit Metadata