zero-day
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches CVE information from the National Vulnerability Database (NIST) at
services.nvd.nist.govand GitHub Security Advisories. These are well-known, authoritative sources for security research data. - [COMMAND_EXECUTION]: Executes standard security and development tools (e.g.,
grep,git,nmap,gh,readelf,checksec) to perform target profiling and analysis. All command usage is consistent with the skill's primary purpose of vulnerability research. - [REMOTE_CODE_EXECUTION]: The automated detection of a pipe to
python3is a false positive; the commandpython3 -m json.toolis a standard Python utility used strictly for formatting and pretty-printing JSON data from NIST, not for executing remote code. - [SAFE]: The skill explicitly mandates authorization for all research targets and emphasizes responsible disclosure policies and the development of non-destructive proof-of-concepts.
Audit Metadata