skills/yaklang/hack-skills/hack/Gen Agent Trust Hub

hack

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a high-level methodology guide for authorized security assessments. It establishes rigorous prerequisites for the agent, including written authorization, rules of engagement, and explicit destruction boundaries, ensuring that activities are conducted legally and safely.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and analyzing untrusted external data, such as web application responses, leaked source code, and security logs.
  • Ingestion points: Untrusted data enters the agent context through attack surface mapping (SKILL.md), source code mining (SOURCE_LEAK.md), and alert triage (BLUE_TEAM.md).
  • Boundary markers: The instructions lack specific technical prompt delimiters but utilize a 'Task Start Gate' to ensure authorization and context before processing data.
  • Capability inventory: The skill describes the use of standard security tools (curl, wget) and references sub-skills for testing various injection vulnerabilities.
  • Sanitization: The skill mandates evidence redaction and provides specific 'Secret liveness gate' protocols to ensure findings are validated without unnecessary risk.
  • [REMOTE_CODE_EXECUTION]: The skill references methodologies for identifying and validating remote code execution vulnerabilities in target systems as part of an authorized audit. It provides instructions to verify such findings non-destructively, for example, by using read-only commands or identifiable test objects.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:50 AM
Security Audit — agent-trust-hub — hack