network-appliance-attacks
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use common security auditing tools including
ike-scanandopensslto evaluate the security posture of perimeter appliances and VPN configurations. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret data from external network appliances, such as service banners, NTLM Type-2 challenges, and SSL certificate information, which could potentially contain malicious payloads if the target is controlled by an adversary.
- Ingestion points: Network responses from external targets (banners, certificates, NTLM Type-2 challenges) described in
SKILL.md. - Boundary markers: No specific delimiters or boundary markers are defined for handling the ingested network data.
- Capability inventory: The skill utilizes tools like
ike-scan,nmap, andopensslto interact with and collect data from network targets. - Sanitization: There are no instructions for sanitizing or escaping content retrieved from the network services before analysis.
Audit Metadata