security-sentinel

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes numerous examples of shell commands for network reconnaissance and vulnerability scanning, including tools such as dig, whois, curl, nmap, nuclei, and testssl.sh. These commands are used as intended for the skill's primary function of performing security assessments.
  • [PROMPT_INJECTION]: The skill interacts with untrusted external data by processing the output of various scanning tools. This creates a surface for indirect prompt injection. While the skill lacks programmatic sanitization, it instructs the agent to manually validate findings, filter for false positives, and use evidence-based reporting, which significantly reduces the risk associated with processing external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 01:56 AM
Security Audit — agent-trust-hub — security-sentinel