burp-suite-testing
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill involves ingesting and analyzing untrusted data from external web applications, which presents a surface for indirect prompt injection.
- Ingestion points: Intercepted HTTP requests, responses, and site map data described in SKILL.md.
- Boundary markers: Includes a mandatory confirmation gate requiring user authorization and target specification.
- Capability inventory: Traffic interception, request modification, and automated vulnerability scanning functions.
- Sanitization: No specific mention of sanitizing tool outputs or external content before interpretation.
Audit Metadata