web-ssti
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of documentation and methodology for security professionals. It does not include any executable scripts, configuration files, or platform-specific command injections.
- [SAFE]: The payloads listed (e.g., Jinja2, Twig, and Java-based gadgets) are standard industry examples used to demonstrate Remote Code Execution (RCE) on target servers during authorized penetration tests. They do not target the agent or the host running the agent.
- [SAFE]: External tool references (tplmap, burp) and research citations (PortSwigger, James Kettle) are well-known and legitimate resources in the cybersecurity community.
Audit Metadata