waf-bypass-techniques
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for identifying Web Application Firewalls using standard command-line tools such as wafw00f and nmap with specialized NSE scripts.- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it instructs the agent on how to process and mutate payloads for potentially untrusted target web applications.
- Ingestion points: Target URLs and injection payloads provided by the user in the prompt.
- Boundary markers: The skill does not define specific delimiters for separating user-provided targets from the analysis logic.
- Capability inventory: The skill references external command execution (wafw00f, nmap) and network request generation for WAF fingerprinting and payload delivery.
- Sanitization: No explicit input sanitization or validation routines are described for the user-provided parameters.
Audit Metadata