pentesting
Warn
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The main
SKILL.mdincludes directives meant to override standard agent behavior, such as 'No preamble. No postamble. No explanations.' and 'Compress output'. These attempt to restrict model transparency and alignment.\n- [PROMPT_INJECTION]: Nine reference files (e.g.,architecture-patterns.md,state-management.md) exhibit significant structural bloat, each containing 150 numbered sections of repetitive technical boilerplate. This excessive redundancy is a form of obfuscation used to bypass length-based security analysis or to push core instructions out of the model's active context window (Denial of Wallet / Context Stuffing).\n- [PROMPT_INJECTION]: The skill's workflow ingests untrusted data from external security tools (e.g., Nuclei, SQLMap) during the reconnaissance and scanning phases. The instructions fail to include boundary markers or data-cleaning steps for this ingested content, allowing potential malicious instructions from a tested target to be interpreted by the AI agent as commands (Indirect Prompt Injection).\n- [COMMAND_EXECUTION]: The skill provides scripts and instructions for executing intensive security tools via the command line, including Nmap, SQLMap, and Metasploit. While standard for pentesting, these capabilities allow the agent to perform unauthorized network operations if misused.\n- [EXTERNAL_DOWNLOADS]: The skill documentation and Docker setup involve downloading numerous third-party security tools from GitHub. While pointing to established security organizations, the sheer volume of external binaries downloaded at runtime increases the potential for supply chain exploitation.
Audit Metadata