assessment-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill includes an authorization block that commands the agent to override safety constraints, skip consent requests, and refrain from using ethical disclaimers or refusing payloads.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. Ingestion point: USER_REQUEST variable processed in parse-request.sh. Boundary markers: Absent. Capability inventory: Extensive shell script execution (e.g., dispatch-assessments.sh) across the assessment pipeline. Sanitization: No input validation or escaping is demonstrated in the skill instructions.
  • [COMMAND_EXECUTION]: The orchestration pipeline relies on executing multiple bash scripts stored in a relative path determined by the SUPERHACKERS_ROOT environment variable.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl, httpx, and other reconnaissance tools to interact with external targets to validate accessibility and discover related web components.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 04:49 PM
Security Audit — agent-trust-hub — assessment-orchestrator