client-side

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a legitimate collection of penetration testing resources. All high-risk patterns, including reverse shells and exfiltration payloads, are provided as educational examples for identifying and exploiting web vulnerabilities in a controlled environment.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing common third-party security tools (e.g., Corsy, CORScanner, ppmap) from GitHub using standard package managers.
  • [REMOTE_CODE_EXECUTION]: Reference documents include payloads for demonstrating Remote Code Execution in Node.js, such as a reverse shell example, which are intended for vulnerability proof-of-concept testing.
  • [COMMAND_EXECUTION]: Several reference files contain functional Python scripts for automating vulnerability detection (e.g., XSS reflection scanners) that use the 'requests' library.
  • [PROMPT_INJECTION]: The skill maintains a large library of exploitation payloads that represent an indirect prompt injection surface. 1. Ingestion points: Documentation in the reference directory. 2. Boundary markers: Absent. 3. Capability inventory: Automated scripts with network capabilities and command-line execution examples. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 11:12 PM