attack-surface-mapping

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructional content for security reconnaissance. It does not contain any executable scripts, network exfiltration commands, or obfuscated payloads. The references to external files are local within the skill environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently processes untrusted data as its primary function is to analyze external websites, which introduces a potential surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to analyze target URLs, capture traffic, and extract information from JavaScript files, HTML, and documentation (SKILL.md, sections 1-3).
  • Boundary markers: There are no explicit instructions or delimiters defined to separate the untrusted data being analyzed from the agent's internal operational logic.
  • Capability inventory: This specific skill is limited to information gathering and mapping; actual vulnerability exploitation is delegated to separate skills (e.g., hack, auth-sec, injection-checking) linked in the handoff section.
  • Sanitization: The methodology does not specify any sanitization, filtering, or validation of the content retrieved from target applications before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 02:13 PM
Security Audit — agent-trust-hub — attack-surface-mapping