network-service-attacks
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous command-line templates for standard networking and security tools, including
nmap,netexec,snmpwalk,ldapsearch, andsmbclient. These are intended to guide a security professional or an agent operating inpentestmode through service auditing. - [INDIRECT_PROMPT_INJECTION]: The skill involves processing untrusted data from network services (such as version strings and service banners) to determine subsequent actions (like searching for CVEs). This creates a theoretical attack surface where a malicious service could return crafted data to influence the agent.
- Ingestion points: Service banners and version information retrieved from network scans.
- Boundary markers: None present in the instructions.
- Capability inventory: The skill utilizes tools capable of network interaction and file system access (via mounting shares).
- Sanitization: No explicit sanitization or validation of the retrieved service strings is mentioned.
Audit Metadata