jxscout-security-research
Warn
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses the sensitive
.envfile located in the project root to retrieve environment variables. - [DATA_EXFILTRATION]: Instructions direct the agent to analyze captured HTTP traffic in the
http_requests/directory, explicitly mentioning the extraction ofAuthorization,Cookie, andSet-Cookieheaders. - [COMMAND_EXECUTION]: The skill depends on the execution of multiple subcommands of the
jxscout-pro-v2CLI tool to perform its functions. - [PROMPT_INJECTION]: The skill processes untrusted data from intercepted web traffic, creating a vulnerability to indirect prompt injection.
- Ingestion points: Captured raw HTTP traffic in
http_requests/and ingested JavaScript/HTML files. - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external content as untrusted data.
- Capability inventory: Access to shell commands via the
jxscout-pro-v2CLI and the ability to create and execute local scripts. - Sanitization: There is no mention of sanitizing or validating the content of intercepted traffic before it enters the agent's context.
- [REMOTE_CODE_EXECUTION]: The documentation suggests the creation and execution of custom scripts within the working directory to facilitate automated security testing and endpoint discovery.
Audit Metadata