expression-language-injection

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill consists exclusively of markdown documentation for security professionals. It does not include any scripts, executables, or configuration files that would execute code on the agent's host system.- [REMOTE_CODE_EXECUTION]: The document contains example payloads for Remote Code Execution (RCE) via SpEL, OGNL, and Java EL. These are provided for educational and diagnostic use in security testing of external target systems and are not designed to execute within the agent's execution environment.- [COMMAND_EXECUTION]: The documentation provides example HTTP commands and sequences (e.g., Spring Cloud Gateway actuator abuse) for security auditing purposes. These are informational templates for the agent to use when interacting with external systems under test.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:23 PM
Security Audit — agent-trust-hub — expression-language-injection