generate-poc
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions and templates for generating security reports. The commands and strings listed (such as SQL injection patterns and paths like /etc/passwd) are standard security research examples intended for inclusion in documentation and do not represent a threat when used as intended.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (SARIF files) which constitutes an attack surface for indirect prompt injection.
- Ingestion points: SARIF trace data is read and parsed by the agent in Step 1.
- Boundary markers: None present; the skill assumes trust in the source/sink data provided in the scan result.
- Capability inventory: The skill is restricted to file writing (vulnerabilities.md) and does not call external network or execution tools directly.
- Sanitization: No explicit sanitization or validation of the SARIF content is mentioned.
- [PROMPT_INJECTION]: No evidence of role-play, bypass markers, or instructions to ignore system guidelines was detected. The instructions follow a professional and procedural format.
Audit Metadata