owasp-zap

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official ZAP Docker image (ghcr.io/zaproxy/zaproxy) and GitHub Actions (zaproxy/action-baseline). These are established, legitimate tools from the ZAP security project (formerly OWASP ZAP) and represent standard industry practice for security auditing.
  • [INDIRECT_PROMPT_INJECTION]: The skill assists with analyzing security scan results and vulnerability reports from external web applications, which constitutes an attack surface for indirect prompt injection if the processed data contains malicious instructions.
  • Ingestion points: Web application scan results (XSS, SQL injection, CSRF) referenced in the instructions and description in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content are provided in the skill documentation.
  • Capability inventory: The skill provides usage instructions and examples but does not include any executable scripts or direct system capabilities.
  • Sanitization: No specific data validation or sanitization steps are defined for the incoming security scan results before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:49 AM
Security Audit — agent-trust-hub — owasp-zap