skills/aeondave/malskill/dirsearch/Gen Agent Trust Hub

dirsearch

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs the agent or user to install the dirsearch package from the standard Python Package Index (PyPI) using pip install dirsearch.
  • [COMMAND_EXECUTION]: The skill provides multiple examples for executing the dirsearch command-line utility to perform directory and file discovery on web targets.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection:
  • Ingestion points: The agent ingests scan results (paths, status codes) from external web servers reached during the dirsearch execution.
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions within the tool's output.
  • Capability inventory: The agent has the capability to run the dirsearch CLI and process its results.
  • Sanitization: Absent; the skill does not specify any validation or sanitization of the server responses before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — dirsearch