web-cypher-injection

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides technical instructions for security auditing and penetration testing related to Neo4j Cypher injection. It accurately describes the mechanics of the vulnerability and how to verify it.
  • [SAFE]: No malicious command execution, data exfiltration, or persistence mechanisms were detected in the skill body or metadata.
  • [SAFE]: The inclusion of tools like curl and burp in the frontmatter and instructions is consistent with the skill's purpose as a penetration testing technique and does not represent a security risk.
  • [SAFE]: The skill provides conceptual payloads for testing SSRF and RCE on target databases; these are examples for auditing external systems and do not contain code that would affect the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — web-cypher-injection