penetration-testing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consistently reinforces the necessity of written authorization and rules of engagement (ROE) before performing any security testing, explicitly citing legal frameworks like the CFAA.
  • [COMMAND_EXECUTION]: The skill contains a functional instruction for the agent to execute a directory listing command (ls ~/.claude/skills/ and similar paths) upon its first activation. This is used solely to verify the installation of recommended companion skills and does not access sensitive user data such as credentials or SSH keys.
  • [SAFE]: The provided methodology references (PTES, OWASP) and tool templates (Nmap, SQLMap, Metasploit) are industry-standard and intended for professional, authorized security auditing.
  • [SAFE]: No obfuscation, base64-encoded payloads, or unauthorized remote code execution patterns were identified within the skill's instructions or scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — penetration-testing