burp-zap-hardened

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Burp Suite proxy history via tools such as get_proxy_history and get_sitemap. While explicit boundary markers for tool outputs are not defined, the skill includes mandatory Security Guardrails that instruct the agent to redact credentials and maintain local analysis. Capabilities like send_to_repeater are strictly governed by instructions to avoid unauthorized authentication.
  • [DATA_EXFILTRATION]: The skill manages sensitive intercepted traffic and addresses exfiltration risks through explicit instructions that forbid transmitting intercepted data, credentials, or metadata to external destinations via network commands, regardless of encoding or the user's stated intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:30 PM
Security Audit — agent-trust-hub — burp-zap-hardened