hunt-nestjs
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes data from external target endpoints which presents a surface for indirect prompt injection attacks.
- Ingestion points: Output from curl commands targeting external URLs defined in SKILL.md.
- Boundary markers: Absent; the agent is not instructed to isolate or disregard potential instructions contained within the external responses.
- Capability inventory: Shell execution capabilities using tools like curl, jq, nc, redis-cli, and grpcurl as specified in SKILL.md.
- Sanitization: Absent; raw data from external sources is piped into processing tools or displayed to the agent context without verification or filtering.
Audit Metadata