skills/seqra/opentaint/generate-poc/Gen Agent Trust Hub

generate-poc

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute various build and containerization commands including './mvnw spring-boot:run', './gradlew bootRun', 'java -jar', and 'docker compose up'.
  • [DYNAMIC_EXECUTION]: The workflow requires the agent to write a custom Python script to a file and execute it at runtime to verify finding validity.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from '.opentaint/tracking/findings/.yaml' files, specifically the 'notes' and 'analyzer report' fields, which could be used to inject malicious instructions into the agent's workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:13 AM
Security Audit — agent-trust-hub — generate-poc