testssl-inspector-expert

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of instructional markdown and documentation. It provides guidance on how to interpret data produced by another tool (testssl-inspector) and does not include any scripts (Python, Node.js, Shell) or binaries.
  • [COMMAND_EXECUTION]: While the skill mentions shell commands like nginx configuration or curl examples in its documentation, these are presented as static remediation examples for the user to follow, not as commands the agent should execute autonomously. The workflow section describes how a user might interact with other CLI tools, which is standard documentation practice.
  • [DATA_EXPOSURE]: The skill references findings stored in ~/.cache/claude-grc/findings/. This is the documented local storage location for the testssl-inspector tool the skill is designed to support. There is no evidence of attempts to exfiltrate this data or access unauthorized paths like .ssh or .aws.
  • [PROMPT_INJECTION]: The instructions are focused on providing security advice and do not contain patterns typical of prompt injection, such as 'Ignore previous instructions' or 'Enable developer mode'. The 'What you will not do' section reinforces safe and ethical usage boundaries for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 03:06 AM
Security Audit — agent-trust-hub — testssl-inspector-expert