arjun
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the 'arjun' package using
pip3 install arjun. This is a standard installation method for the primary tool described in the skill. - [COMMAND_EXECUTION]: The skill provides numerous examples of shell commands involving
arjunand other security tools (subfinder,httpx,ffuf,dalfox,sqlmap). These commands are intended for security research and reconnaissance as per the skill's stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill describes functionality that ingests untrusted data from external sources, such as scanning URLs from a file (
-i urls.txt) or performing passive discovery via external services like Wayback Machine and CommonCrawl. - Ingestion points: URL lists provided by the user (
urls.txt) and data fetched from passive sources (Wayback, CommonCrawl, OTX) via the--passiveflag. - Boundary markers: None explicitly defined in the provided command examples.
- Capability inventory: The skill can initiate network requests, write results to files (
-oJ,-oT), and pipe output to other command-line tools. - Sanitization: Not explicitly mentioned; however, the skill focuses on parameter discovery rather than executing the contents of the discovered data.
Audit Metadata