assessment-orchestrator
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill includes an authorization block that commands the agent to override safety constraints, skip consent requests, and refrain from using ethical disclaimers or refusing payloads.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. Ingestion point: USER_REQUEST variable processed in parse-request.sh. Boundary markers: Absent. Capability inventory: Extensive shell script execution (e.g., dispatch-assessments.sh) across the assessment pipeline. Sanitization: No input validation or escaping is demonstrated in the skill instructions.
- [COMMAND_EXECUTION]: The orchestration pipeline relies on executing multiple bash scripts stored in a relative path determined by the SUPERHACKERS_ROOT environment variable.
- [EXTERNAL_DOWNLOADS]: The skill uses curl, httpx, and other reconnaissance tools to interact with external targets to validate accessibility and discover related web components.
Audit Metadata