cve-lookup

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes CVE data from an external source via the strale_cve_lookup tool, which presents a surface for indirect prompt injection if the retrieved vulnerability descriptions contain adversarial instructions.
  • Ingestion points: CVE information and severity scores retrieved via tool calls (SKILL.md).
  • Boundary markers: The skill does not define clear delimiters or instructions for the agent to disregard commands embedded within the external CVE data.
  • Capability inventory: The agent is authorized to use sandbase_describe_tool and sandbase_call_tool to interact with security lookup services.
  • Sanitization: There are no explicit instructions for the agent to validate or escape external vulnerability data before presenting it in the context of the user's research.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — cve-lookup