dalfox
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
--found-action <cmd>flag which allows the execution of arbitrary shell commands whenever a vulnerability is discovered. This is a powerful feature intended for automation (e.g., logging or notifications). - [DATA_EXFILTRATION]: The documentation provides examples of using
curlwithin the--found-actionflag to exfiltrate scan results ($POCURL) to external webhooks, such as Slack. This is the intended purpose of the tool for reporting, but involves sending local scan data to a remote server. - [INDIRECT_PROMPT_INJECTION]: As a security scanning tool that processes external URLs and web responses, the skill is inherently exposed to untrusted data. A malicious web page could include content designed to influence the agent's behavior during the analysis phase.
- Ingestion points: Reads data from external URLs via
dalfox url,dalfox pipe, anddalfox file(SKILL.md). - Boundary markers: None explicitly defined in the provided markdown to separate scan results from agent instructions.
- Capability inventory: Uses subprocess calls to run
dalfoxand provides shell execution via--found-action(SKILL.md). - Sanitization: None described for the output of the scans before it reaches the agent's context.
- [SAFE]: The skill references and integrates with several well-known and trusted security tools and repositories, including
github.com/tomnomnom/gfandgithub.com/1ndianl33t/gf-patterns. These references are standard for the security research community.
Audit Metadata