openvas
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of standard service wrappers and command-line utilities for the Greenbone Vulnerability Manager (GVM). Evidence includes commands like
gvm-start,gvm-stop,gvm-check-setup, andgvm-cliused for service control and XML-based task management. These are documented as reference examples for the intended vulnerability scanning functionality. - [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that ingests external target lists and processes scanner results, representing a typical data ingestion surface for vulnerability assessment tools.
- Ingestion points: The skill utilizes approved target lists and processes raw scanner output as described in the 'Inputs' and 'Procedure' sections.
- Boundary markers: Present; the 'Safety Boundaries' section explicitly instructs the agent to keep operations within approved targets and windows.
- Capability inventory: The skill uses
gvm-clito perform network-based vulnerability scans. - Sanitization: The skill relies on analyst triage and manual validation of findings as a control mechanism rather than automated code-level sanitization.
Audit Metadata