generate-poc
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various build and containerization commands including './mvnw spring-boot:run', './gradlew bootRun', 'java -jar', and 'docker compose up'.
- [DYNAMIC_EXECUTION]: The workflow requires the agent to write a custom Python script to a file and execute it at runtime to verify finding validity.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from '.opentaint/tracking/findings/.yaml' files, specifically the 'notes' and 'analyzer report' fields, which could be used to inject malicious instructions into the agent's workflow.
Audit Metadata