web-cypher-injection
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides technical instructions for security auditing and penetration testing related to Neo4j Cypher injection. It accurately describes the mechanics of the vulnerability and how to verify it.
- [SAFE]: No malicious command execution, data exfiltration, or persistence mechanisms were detected in the skill body or metadata.
- [SAFE]: The inclusion of tools like
curlandburpin the frontmatter and instructions is consistent with the skill's purpose as a penetration testing technique and does not represent a security risk. - [SAFE]: The skill provides conceptual payloads for testing SSRF and RCE on target databases; these are examples for auditing external systems and do not contain code that would affect the local environment.
Audit Metadata