skills/simota/agent-skills/siege/Gen Agent Trust Hub

siege

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted data such as API responses, OpenTelemetry traces, and system logs to perform load and chaos testing analysis.
  • Ingestion points: API response data processed during load tests (described in reference/load-testing-guide.md), trace spans from distributed systems (reference/test-strategy-2026.md), and test survivor output in mutation testing (reference/mutation-testing-guide.md).
  • Boundary markers: The instructions focus on defining hypotheses and steady states but lack explicit sanitization or escaping instructions for data interpolated from these external sources.
  • Capability inventory: The skill interacts with powerful CLI tools including k6, Locust, and various chaos engineering platforms (e.g., LitmusChaos, AWS FIS).
  • Sanitization: No specific sanitization or filtering logic is provided for handling content returned from external API endpoints or logs.
  • [EXTERNAL_DOWNLOADS]: The skill configuration and reference documents facilitate the use of industry-standard testing tools and GitHub Actions from established providers.
  • Evidence: The skill references google/clusterfuzzlite/actions and grafana/k6-action, which are maintained by a trusted organization (Google) and a well-known service (Grafana Labs) respectively. These references are documented neutrally as they align with standard development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — siege