httpx
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides documentation and command syntax for executing the
httpxcommand-line utility to probe network assets. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze data from external, potentially untrusted web servers, creating an attack surface where malicious content in web responses could influence agent behavior.
- Ingestion points: Probed web metadata including HTTP titles, status codes, and technology hints captured by
httpx(SKILL.md). - Boundary markers: The skill does not define specific delimiters or instructions to treat the captured web metadata as untrusted content.
- Capability inventory: The skill uses shell command execution to interact with the host system and external tools (SKILL.md).
- Sanitization: There are no instructions for sanitizing or validating external web data before it is recorded as evidence or used to shape subsequent analysis steps.
Audit Metadata