web-command-injection
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown documentation (SKILL.md and cheatsheet.md) providing educational content on OS Command Injection techniques.
- [SAFE]: The provided payloads and methodologies (e.g., time-based delays, Out-of-Band callbacks via DNS/HTTP) are industry-standard practices for penetration testing and bug bounty hunting.
- [SAFE]: No executable code, automated scripts, or hidden commands are included. The skill serves as a reference for the agent to use when performing authorized security testing.
- [SAFE]: The documentation includes explicit ethical guidance, advising to use 'least-action' proofs and to avoid destructive commands or exfiltration beyond what is necessary to prove impact.
Audit Metadata