testssl-sh
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists of instructional content and command templates; it does not include any scripts, binaries, or configuration files.
- [SAFE]: The provided commands and procedures are standard practices for TLS security reviews and certificate hygiene checks during authorized testing.
- [INDIRECT_PROMPT_INJECTION]: The skill processes target hostnames as input. Evidence chain: 1. Ingestion points: Target URLs in SKILL.md; 2. Boundary markers: None present; 3. Capability inventory: Bash command execution for tool usage; 4. Sanitization: None explicitly mentioned. The risk is considered safe for the intended pentesting use case.
Audit Metadata