penetration-testing-expert

Fail

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides and encourages the use of invasive network tools such as nmap, masscan, sqlmap, and the Metasploit Framework. The agent is granted Bash tool access to execute these commands, which are used for service enumeration and automated exploitation.
  • [DYNAMIC_EXECUTION]: The references/EXAMPLES.md file contains instructions for using msfvenom to generate malicious executable payloads (Meterpreter) in .exe, .elf, and .php formats for multiple operating systems.
  • [CREDENTIALS_UNSAFE]: Includes a Burp Suite extension script that uses regex patterns to identify and extract sensitive information from HTTP responses, including AWS Access Keys (AKIA...), credit card numbers, and generic API keys.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements web crawling and vulnerability scanning logic that ingests untrusted data from external targets.
  • Ingestion points: Data retrieved from target URLs via requests and processed by the WebVulnScanner class and Burp Suite extension.
  • Boundary markers: None provided in the examples to prevent the agent from interpreting instructions embedded in the processed target data.
  • Capability inventory: The skill has access to shell execution (Bash), file modification (Write, Edit), and direct network requests.
  • Sanitization: There is no evidence of input validation or content sanitization for data processed during crawling or vulnerability scanning.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — penetration-testing-expert