web-command-injection

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown documentation (SKILL.md and cheatsheet.md) providing educational content on OS Command Injection techniques.
  • [SAFE]: The provided payloads and methodologies (e.g., time-based delays, Out-of-Band callbacks via DNS/HTTP) are industry-standard practices for penetration testing and bug bounty hunting.
  • [SAFE]: No executable code, automated scripts, or hidden commands are included. The skill serves as a reference for the agent to use when performing authorized security testing.
  • [SAFE]: The documentation includes explicit ethical guidance, advising to use 'least-action' proofs and to avoid destructive commands or exfiltration beyond what is necessary to prove impact.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:01 PM
Security Audit — agent-trust-hub — web-command-injection