skills/aeondave/malskill/dalfox/Gen Agent Trust Hub

dalfox

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the --found-action <cmd> flag which allows the execution of arbitrary shell commands whenever a vulnerability is discovered. This is a powerful feature intended for automation (e.g., logging or notifications).
  • [DATA_EXFILTRATION]: The documentation provides examples of using curl within the --found-action flag to exfiltrate scan results ($POCURL) to external webhooks, such as Slack. This is the intended purpose of the tool for reporting, but involves sending local scan data to a remote server.
  • [INDIRECT_PROMPT_INJECTION]: As a security scanning tool that processes external URLs and web responses, the skill is inherently exposed to untrusted data. A malicious web page could include content designed to influence the agent's behavior during the analysis phase.
  • Ingestion points: Reads data from external URLs via dalfox url, dalfox pipe, and dalfox file (SKILL.md).
  • Boundary markers: None explicitly defined in the provided markdown to separate scan results from agent instructions.
  • Capability inventory: Uses subprocess calls to run dalfox and provides shell execution via --found-action (SKILL.md).
  • Sanitization: None described for the output of the scans before it reaches the agent's context.
  • [SAFE]: The skill references and integrates with several well-known and trusted security tools and repositories, including github.com/tomnomnom/gf and github.com/1ndianl33t/gf-patterns. These references are standard for the security research community.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — dalfox