skills/timsonner/agent-skills/openvas/Gen Agent Trust Hub

openvas

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents the use of standard service wrappers and command-line utilities for the Greenbone Vulnerability Manager (GVM). Evidence includes commands like gvm-start, gvm-stop, gvm-check-setup, and gvm-cli used for service control and XML-based task management. These are documented as reference examples for the intended vulnerability scanning functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that ingests external target lists and processes scanner results, representing a typical data ingestion surface for vulnerability assessment tools.
  • Ingestion points: The skill utilizes approved target lists and processes raw scanner output as described in the 'Inputs' and 'Procedure' sections.
  • Boundary markers: Present; the 'Safety Boundaries' section explicitly instructs the agent to keep operations within approved targets and windows.
  • Capability inventory: The skill uses gvm-cli to perform network-based vulnerability scans.
  • Sanitization: The skill relies on analyst triage and manual validation of findings as a control mechanism rather than automated code-level sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:38 AM
Security Audit — agent-trust-hub — openvas