default-credentials

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a documentation and methodology guide for web security auditing. It contains no executable scripts, hardcoded credentials, or unauthorized persistence mechanisms.\n- [COMMAND_EXECUTION]: The documentation provides example bash command templates for security tools like Hydra and curl. These are used for testing login endpoints and auditing password policies against a user-defined target.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes a methodology for ingesting data from external web targets to identify frameworks, which constitutes a potential indirect prompt injection surface. The analysis is as follows:\n
  • Ingestion points: HTTP headers, cookies, HTML source markers, and robots.txt entries (SKILL.md).\n
  • Boundary markers: None identified to mitigate processing of instructions that might be embedded in target response data.\n
  • Capability inventory: Execution of network-interactive tools including curl and Hydra (SKILL.md).\n
  • Sanitization: No specific sanitization or validation of the external platform signals is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:35 PM
Security Audit — agent-trust-hub — default-credentials