vuln-triage

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is composed entirely of markdown instructions and does not contain any executable scripts, shell commands, or binaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to process external data such as CVE details and scanner findings. This creates a surface for indirect prompt injection where an attacker-controlled vulnerability report could attempt to manipulate the agent's output. However, the skill lacks any tool access or capabilities that would allow for data exfiltration or system modification.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were identified during the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 11:33 AM
Security Audit — agent-trust-hub — vuln-triage