amass
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents workflows that ingest large amounts of untrusted data from external infrastructure (DNS records, search engine results, and third-party APIs) and pipes this data into downstream tools such as
httpx,nmap, andeyewitness. - Ingestion points:
SKILL.mdandreferences/config.mddefine processes whereamassandtheHarvestercollect external subdomain names and infrastructure data. - Boundary markers: No specific delimiters or "ignore instructions" warnings are present in the documentation for the data pipeline.
- Capability inventory: The skill utilizes shell execution for several reconnaissance and mapping tools (
amass,dnsx,httpx,nmap,theHarvester,eyewitness). - Sanitization: The skill relies on the individual tools' internal sanitization of external strings; however, this is standard behavior for security-focused reconnaissance workflows.
- [COMMAND_EXECUTION]: The skill provides numerous examples and a bash script template for executing security tools via the command line. These commands are intended for authorized security testing and infrastructure discovery within a laboratory or professional environment.
Audit Metadata