skills/aeondave/malskill/arjun/Gen Agent Trust Hub

arjun

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the 'arjun' package using pip3 install arjun. This is a standard installation method for the primary tool described in the skill.
  • [COMMAND_EXECUTION]: The skill provides numerous examples of shell commands involving arjun and other security tools (subfinder, httpx, ffuf, dalfox, sqlmap). These commands are intended for security research and reconnaissance as per the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes functionality that ingests untrusted data from external sources, such as scanning URLs from a file (-i urls.txt) or performing passive discovery via external services like Wayback Machine and CommonCrawl.
  • Ingestion points: URL lists provided by the user (urls.txt) and data fetched from passive sources (Wayback, CommonCrawl, OTX) via the --passive flag.
  • Boundary markers: None explicitly defined in the provided command examples.
  • Capability inventory: The skill can initiate network requests, write results to files (-oJ, -oT), and pipe output to other command-line tools.
  • Sanitization: Not explicitly mentioned; however, the skill focuses on parameter discovery rather than executing the contents of the discovered data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — arjun