web-app-penetration-testing
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill uses tools and domains associated with the documented vendor usestrix.
- [COMMAND_EXECUTION]: The skill defines workflows for executing the strix command-line utility. This is consistent with the skill's stated purpose of performing automated web application penetration testing and requires the user to have the tool installed.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of target URLs and testing instructions for the pentesting engine.
- Ingestion points: Target URLs and instruction strings passed to the CLI tool in SKILL.md.
- Boundary markers: The skill uses standard CLI flags (-t, --instruction) to separate input data.
- Capability inventory: Shell execution of the strix CLI tool.
- Sanitization: The skill relies on the underlying strix tool to handle the input data for security scanning purposes.
Audit Metadata