web-ssti

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation and methodology for security professionals. It does not include any executable scripts, configuration files, or platform-specific command injections.
  • [SAFE]: The payloads listed (e.g., Jinja2, Twig, and Java-based gadgets) are standard industry examples used to demonstrate Remote Code Execution (RCE) on target servers during authorized penetration tests. They do not target the agent or the host running the agent.
  • [SAFE]: External tool references (tplmap, burp) and research citations (PortSwigger, James Kettle) are well-known and legitimate resources in the cybersecurity community.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — web-ssti