django-attack-probe

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill includes instructions to probe for sensitive system files, specifically /etc/passwd, as part of a path traversal vulnerability test (finding DJ-FILE-001).
  • [COMMAND_EXECUTION]: The instructions direct the agent to perform active security probing, including SQL injection payloads (finding DJ-SQLI-001) and testing for default credentials such as 'admin/admin' (finding DJ-ADMIN-002).
  • [DATA_EXFILTRATION]: The skill creates an indirect prompt injection surface by ingesting and analyzing untrusted web responses from the target application (e.g., Django debug pages, API responses) without explicit boundary markers or sanitization logic. Ingestion points: responses from endpoints such as /, /admin/, and /api/ in SKILL.md. Capability inventory: network requests (GET, POST, PATCH, DELETE) and file system read attempts. Boundary markers: Absent. Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 12:45 PM
Security Audit — agent-trust-hub — django-attack-probe