whatweb
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides standard command syntax for the whatweb utility, including aggression levels and logging options, which are appropriate for its intended use.
- [PROMPT_INJECTION]: The skill involves processing external technology signatures from web servers. While this is an indirect prompt injection surface (Ingestion points: whatweb output; Boundary markers: none; Capability inventory: whatweb; Sanitization: none), the workflow includes instructions for manual validation and labeling of unverified hints.
- [SAFE]: No evidence of obfuscation, hardcoded credentials, or persistence mechanisms was found in the skill content.
Audit Metadata