http-load-testing

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions for executing network benchmarking tools such as oha, hey, ab, wrk, and curl. These tools are used appropriately for measuring API throughput and latency.\n- [EXTERNAL_DOWNLOADS]: Users are directed to install the oha tool via standard, reputable package managers including Homebrew (brew install oha) and Cargo (cargo install oha).\n- [METADATA_POISONING]: The skill's allowed-tools metadata in the YAML frontmatter fails to include the oha command, which is the primary tool described throughout the instructions. While this inconsistency may prevent the agent from executing the recommended commands, it appears to be a configuration error rather than a malicious attempt to deceive.\n- [INDIRECT_PROMPT_INJECTION]: The skill presents an indirect prompt injection attack surface by facilitating the processing of data from external network endpoints.\n
  • Ingestion points: The skill utilizes URLs provided as arguments and reads request data from external files (request.json). It also demonstrates parsing HTTP response bodies using jq (e.g., in SKILL.md).\n
  • Boundary markers: No specific delimiters or instructions to disregard embedded content in tool outputs are provided in the skill's examples.\n
  • Capability inventory: The skill leverages network-access tools (oha, curl, wrk) capable of communicating with arbitrary services.\n
  • Sanitization: The skill does not include examples or instructions for sanitizing inputs or validating external response data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 09:43 AM