owasp-top-10-testing
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute the
strixCLI tool for security auditing. This tool is a vendor-owned resource belonging to usestrix and is used for its intended purpose of vulnerability scanning. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates scanning of external targets (URLs and source code repositories), which constitutes a potential ingestion point for untrusted data. However, given the skill's primary function is to identify vulnerabilities within such data, this interaction is considered safe and appropriate for the use case.
Audit Metadata