waf-bypass-techniques

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for identifying Web Application Firewalls using standard command-line tools such as wafw00f and nmap with specialized NSE scripts.- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it instructs the agent on how to process and mutate payloads for potentially untrusted target web applications.
  • Ingestion points: Target URLs and injection payloads provided by the user in the prompt.
  • Boundary markers: The skill does not define specific delimiters for separating user-provided targets from the analysis logic.
  • Capability inventory: The skill references external command execution (wafw00f, nmap) and network request generation for WAF fingerprinting and payload delivery.
  • Sanitization: No explicit input sanitization or validation routines are described for the user-provided parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:14 PM
Security Audit — agent-trust-hub — waf-bypass-techniques