skills/rifteo/skills/pentest-report/Gen Agent Trust Hub

pentest-report

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and format penetration testing findings from external sources, which creates a vulnerability surface for instructions embedded in that data to influence the agent's behavior during report generation. \n
  • Ingestion points: Findings provided by the user in the conversation context or retrieved from previous outputs like finding-writer and ENGAGEMENT.md (SKILL.md). \n
  • Boundary markers: The instructions lack specific delimiters or instructions to treat findings as untrusted data or to ignore embedded commands. \n
  • Capability inventory: The skill has the capability to read from the current environment and format data into files based on templates in the references/ directory (SKILL.md). \n
  • Sanitization: There are no defined mechanisms for filtering, escaping, or validating the content of findings before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:09 AM
Security Audit — agent-trust-hub — pentest-report