okta-attack

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains functional Bash scripts for DNS resolution, HTTP redirection tracking, and Okta API interaction. These scripts utilize system utilities like curl and dnsx to automate reconnaissance against target infrastructure.
  • [EXTERNAL_DOWNLOADS]: The documentation references external security tools on GitHub and identifies multiple third-party phishing frameworks. It also employs network commands to fetch metadata and session information from Okta-related domains.
  • [PROMPT_INJECTION]: The skill includes an indirect prompt injection surface. 1. Ingestion points: Untrusted data enters the agent context via placeholders such as , , and in SKILL.md. 2. Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within these inputs. 3. Capability inventory: The skill performs subprocess calls using curl and dnsx across multiple scripts. 4. Sanitization: There is no implementation of input validation or escaping for user-supplied variables before they are interpolated into shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 10:44 AM
Security Audit — agent-trust-hub — okta-attack