security-arsenal
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a static knowledge base and payload library for security professionals. While it contains numerous patterns related to web vulnerabilities (XSS, SQLi, RCE, etc.), these are provided as instructional examples and templates for testing external targets, rather than instructions for the agent to perform malicious acts on the local host or exfiltrate the user's private data.
- [COMMAND_EXECUTION]: The document lists various shell commands and injection payloads (e.g.,
id,sleep,curl,nslookup). These are documented strictly for use in security testing scenarios to verify command injection vulnerabilities in remote applications. - [DATA_EXFILTRATION]: Payloads involving external domains such as
attacker.comandburpcollaborator.netare included. These are standard industry placeholders for Out-of-Band (OOB) security testing to confirm vulnerabilities like SSRF, XXE, and Blind XSS by triggering a network callback to a controlled listener.
Audit Metadata