testssl-inspector-expert
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of instructional markdown and documentation. It provides guidance on how to interpret data produced by another tool (
testssl-inspector) and does not include any scripts (Python, Node.js, Shell) or binaries. - [COMMAND_EXECUTION]: While the skill mentions shell commands like
nginxconfiguration orcurlexamples in its documentation, these are presented as static remediation examples for the user to follow, not as commands the agent should execute autonomously. The workflow section describes how a user might interact with other CLI tools, which is standard documentation practice. - [DATA_EXPOSURE]: The skill references findings stored in
~/.cache/claude-grc/findings/. This is the documented local storage location for thetestssl-inspectortool the skill is designed to support. There is no evidence of attempts to exfiltrate this data or access unauthorized paths like.sshor.aws. - [PROMPT_INJECTION]: The instructions are focused on providing security advice and do not contain patterns typical of prompt injection, such as 'Ignore previous instructions' or 'Enable developer mode'. The 'What you will not do' section reinforces safe and ethical usage boundaries for the agent.
Audit Metadata