web-app-penetration-testing

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill uses tools and domains associated with the documented vendor usestrix.
  • [COMMAND_EXECUTION]: The skill defines workflows for executing the strix command-line utility. This is consistent with the skill's stated purpose of performing automated web application penetration testing and requires the user to have the tool installed.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of target URLs and testing instructions for the pentesting engine.
  • Ingestion points: Target URLs and instruction strings passed to the CLI tool in SKILL.md.
  • Boundary markers: The skill uses standard CLI flags (-t, --instruction) to separate input data.
  • Capability inventory: Shell execution of the strix CLI tool.
  • Sanitization: The skill relies on the underlying strix tool to handle the input data for security scanning purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 11:37 PM
Security Audit — agent-trust-hub — web-app-penetration-testing