probe
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it is designed to ingest and process untrusted data from target applications and third-party security tools.
- Ingestion points: The skill processes raw HTTP responses, GraphQL/OpenAPI schemas, and scan results from tools like ZAP, Burp, and Nuclei as documented in its API and mobile DAST references.
- Boundary markers: The instructions emphasize a "Trust nothing" philosophy and require all findings to be reproducibility-verified and clearly labeled as "Confirmed" or "Unconfirmed" in a structured report format.
- Capability inventory: Performs network requests via various security tools and executes subprocess commands for scanning, reconnaissance, and fuzzing activities.
- Sanitization: The workflow incorporates manual validation steps and human-readable evidence requirements to prevent the agent from blindly following instructions embedded in external test data.
Audit Metadata