middleware-tactics

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides standard security reconnaissance commands using tools like whatweb, curl, and nmap to identify middleware versions and open ports. These are common administrative and auditing commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user input in the form of target IPs or URLs for scanning. It provides a structured methodology for identifying and exploiting middleware vulnerabilities, but does not autonomously execute high-risk operations or ingest untrusted data in a way that would lead to unauthorized control flow.
  • [REMOTE_CODE_EXECUTION]: While the skill discusses Remote Code Execution (RCE) and WebShell deployment (e.g., WAR files for Tomcat/WebLogic), it does so as a methodology for penetration testing. It does not contain any automated exploit scripts or remote code execution logic directed at the agent's environment.
  • [DATA_EXPOSURE]: The skill mentions common administrative paths and default credential testing as part of a methodology. It does not contain or exfiltrate any actual sensitive data or hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:49 PM
Security Audit — agent-trust-hub — middleware-tactics