ai-llm-app-attack

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The content is purely informational markdown text intended for security researchers and penetration testers.
  • [NO_CODE]: The skill does not provide any scripts, executables, or binary files, functioning only as a knowledge base.
  • [PROMPT_INJECTION]: The skill identifies the attack surface for indirect prompt injection. Ingestion points: RAG documents, webpages, emails, and tool return values. Boundary markers: None. Capability inventory: Code interpreters, fetch tools, file tools, SQL tools, and shell environments. Sanitization: Identifies risks of missing sanitization for outputs passed to eval or SQL tools.
  • [REMOTE_CODE_EXECUTION]: The documentation describes conceptual RCE vectors via agent tool abuse and vulnerable model deserialization using pickle-based torch.load.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:37 AM
Security Audit — agent-trust-hub — ai-llm-app-attack