web-arsenal
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous CLI commands for security-oriented tools like
sqlmap,nuclei,ffuf, andarjun. These commands are intended for the agent to execute on the local system to interact with external targets.\n- [INDIRECT_PROMPT_INJECTION]: The agent is instructed to analyze and interpret data retrieved from external, potentially untrusted web servers via enumeration and crawling tools.\n - Ingestion points: Results and output from web request tools (
curl) and security scanners (whatweb,nuclei,katana) as described in SKILL.md.\n - Boundary markers: The skill lacks explicit instructions or delimiters to prevent the agent from being influenced by instructions hidden within the HTML, headers, or JS of a target website.\n
- Capability inventory: The agent has the capability to execute complex shell commands and initiate network requests based on the tools listed.\n
- Sanitization: No sanitization or filtering of external tool output is mandated before the agent processes the information.
Audit Metadata