hunt-sqli

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and analyze data from external web resources, which introduces an attack surface where malicious instructions embedded in target responses could influence agent behavior.\n- Ingestion points: The agent is instructed to capture and process parameters, HTTP headers (User-Agent, Referer, X-Forwarded-For), and response bodies from arbitrary web endpoints.\n- Boundary markers: There are no instructions for the agent to use delimiters or specific safety markers to differentiate between the agent's instructions and the untrusted data being analyzed.\n- Capability inventory: The agent has access to powerful diagnostic and scanning capabilities through its instructions to use curl, sqlmap, and grep.\n- Sanitization: No sanitization or validation protocols are specified for the external data before it is evaluated by the agent for vulnerability confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:31 AM
Security Audit — agent-trust-hub — hunt-sqli