default-credentials
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a documentation and methodology guide for web security auditing. It contains no executable scripts, hardcoded credentials, or unauthorized persistence mechanisms.\n- [COMMAND_EXECUTION]: The documentation provides example bash command templates for security tools like Hydra and curl. These are used for testing login endpoints and auditing password policies against a user-defined target.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes a methodology for ingesting data from external web targets to identify frameworks, which constitutes a potential indirect prompt injection surface. The analysis is as follows:\n
- Ingestion points: HTTP headers, cookies, HTML source markers, and robots.txt entries (SKILL.md).\n
- Boundary markers: None identified to mitigate processing of instructions that might be embedded in target response data.\n
- Capability inventory: Execution of network-interactive tools including curl and Hydra (SKILL.md).\n
- Sanitization: No specific sanitization or validation of the external platform signals is described.
Audit Metadata