ai-llm-app-attack
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [SAFE]: The content is purely informational markdown text intended for security researchers and penetration testers.
- [NO_CODE]: The skill does not provide any scripts, executables, or binary files, functioning only as a knowledge base.
- [PROMPT_INJECTION]: The skill identifies the attack surface for indirect prompt injection. Ingestion points: RAG documents, webpages, emails, and tool return values. Boundary markers: None. Capability inventory: Code interpreters, fetch tools, file tools, SQL tools, and shell environments. Sanitization: Identifies risks of missing sanitization for outputs passed to eval or SQL tools.
- [REMOTE_CODE_EXECUTION]: The documentation describes conceptual RCE vectors via agent tool abuse and vulnerable model deserialization using pickle-based torch.load.
Audit Metadata