skills/timsonner/agent-skills/nuclei/Gen Agent Trust Hub

nuclei

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides various command-line examples for executing the nuclei security tool. These include scanning single targets, using host lists, and applying specific vulnerability tags.\n- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection because the agent processes output generated from external, potentially hostile network targets.\n
  • Ingestion points: The agent is instructed to triage results from output files (e.g., contoso-nuclei.txt) that contain data fetched from external web servers.\n
  • Boundary markers: Absent. No specific delimiters or instructions are provided to help the agent distinguish between tool metadata and potentially malicious instructions embedded in the scanned target's responses.\n
  • Capability inventory: The skill enables the execution of CLI tools via shell commands as defined in the SKILL.md file.\n
  • Sanitization: Absent. There is no mention of filtering or sanitizing the tool output before it is evaluated by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:39 AM
Security Audit — agent-trust-hub — nuclei