cve-lookup
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes CVE data from an external source via the
strale_cve_lookuptool, which presents a surface for indirect prompt injection if the retrieved vulnerability descriptions contain adversarial instructions. - Ingestion points: CVE information and severity scores retrieved via tool calls (SKILL.md).
- Boundary markers: The skill does not define clear delimiters or instructions for the agent to disregard commands embedded within the external CVE data.
- Capability inventory: The agent is authorized to use
sandbase_describe_toolandsandbase_call_toolto interact with security lookup services. - Sanitization: There are no explicit instructions for the agent to validate or escape external vulnerability data before presenting it in the context of the user's research.
Audit Metadata