quarkus-verification
Fail
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: HIGHINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to review various tool-generated reports, such as JaCoCo coverage reports and OWASP Dependency-Check findings. While these are generated from the project's own code, they represent an ingestion surface for external data that could theoretically influence agent behavior. Ingestion points include 'target/site/jacoco/index.html' and 'target/dependency-check-report.html' (SKILL.md). The skill has shell execution capabilities (mvn, docker, curl). No explicit boundary markers or sanitization steps are defined for the content of these reports.- [COMMAND_EXECUTION]: The skill utilizes multiple system commands to perform project lifecycle tasks, including 'mvn' for build and test automation, 'docker' for running security tools and container tests, and 'curl' for interacting with the application's health and API endpoints. These are standard operations performed on local or trusted project resources.- [EXTERNAL_DOWNLOADS]: The skill triggers downloads from well-known and trusted external services. It fetches Maven dependencies from standard registries and pulls a security scanning image from the official OWASP organization on Docker Hub ('owasp/zap2docker-stable'). These interactions target established services and are essential for the skill's stated purpose.
Recommendations
- HIGH: Downloads and executes remote code from: http://localhost:8080/q/openapi - DO NOT USE without thorough review
Audit Metadata