jxscout-security-research

Warn

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses the sensitive .env file located in the project root to retrieve environment variables.
  • [DATA_EXFILTRATION]: Instructions direct the agent to analyze captured HTTP traffic in the http_requests/ directory, explicitly mentioning the extraction of Authorization, Cookie, and Set-Cookie headers.
  • [COMMAND_EXECUTION]: The skill depends on the execution of multiple subcommands of the jxscout-pro-v2 CLI tool to perform its functions.
  • [PROMPT_INJECTION]: The skill processes untrusted data from intercepted web traffic, creating a vulnerability to indirect prompt injection.
  • Ingestion points: Captured raw HTTP traffic in http_requests/ and ingested JavaScript/HTML files.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external content as untrusted data.
  • Capability inventory: Access to shell commands via the jxscout-pro-v2 CLI and the ability to create and execute local scripts.
  • Sanitization: There is no mention of sanitizing or validating the content of intercepted traffic before it enters the agent's context.
  • [REMOTE_CODE_EXECUTION]: The documentation suggests the creation and execution of custom scripts within the working directory to facilitate automated security testing and endpoint discovery.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 21, 2026, 05:13 AM
Security Audit — agent-trust-hub — jxscout-security-research