skills/timsonner/agent-skills/nikto/Gen Agent Trust Hub

nikto

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions and examples for executing the nikto command-line tool to perform web server security audits. All examples utilize standard flags for host specification, port selection, and report generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting and processing data from external web servers via the scanner's output.
  • Ingestion points: Data retrieved from external web servers during scanning operations (SKILL.md).
  • Boundary markers: Absent. The skill does not define specific delimiters for separating tool output from the agent's primary instructions.
  • Capability inventory: Subprocess execution of the nikto utility (SKILL.md).
  • Sanitization: No specific sanitization or filtering of the tool's output is mentioned in the procedure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:38 AM
Security Audit — agent-trust-hub — nikto