pentest-report
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and format penetration testing findings from external sources, which creates a vulnerability surface for instructions embedded in that data to influence the agent's behavior during report generation. \n
- Ingestion points: Findings provided by the user in the conversation context or retrieved from previous outputs like finding-writer and ENGAGEMENT.md (SKILL.md). \n
- Boundary markers: The instructions lack specific delimiters or instructions to treat findings as untrusted data or to ignore embedded commands. \n
- Capability inventory: The skill has the capability to read from the current environment and format data into files based on templates in the references/ directory (SKILL.md). \n
- Sanitization: There are no defined mechanisms for filtering, escaping, or validating the content of findings before they are processed by the agent.
Audit Metadata