race-condition
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines procedures for interacting with external web applications, creating a surface for indirect prompt injection where malicious instructions could be embedded in server responses. \n
- Ingestion points: The agent is instructed to capture and analyze state-changing requests and responses from target web applications (SKILL.md). \n
- Boundary markers: The skill does not define specific boundary markers for separating instructional content from data received from target web applications. \n
- Capability inventory: The skill utilizes network communication tools and libraries (Turbo Intruder, h2spacex, Burp Suite) to execute parallel HTTP requests (SKILL.md, Sections 5, 7, 9.4). \n
- Sanitization: No explicit sanitization or validation of data retrieved from target web applications is described. \n- [EXTERNAL_DOWNLOADS]: The skill references several external resources and tools for race condition testing. \n
- Fetches documentation and tool information from PortSwigger's GitHub repository. \n
- References the
Raceocatutility from a public GitHub repository. \n - References the
h2spacexlibrary from a public GitHub repository. \n - Provides links to official vulnerability details on the National Vulnerability Database (NVD).
Audit Metadata