dnsx
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download wordlists and DNS resolver configurations from external sources.
- Fetches a subdomain wordlist from Assetnote's GitHub repository:
https://raw.githubusercontent.com/assetnote/commonspeak2-wordlists/master/subdomains/subdomains.txt. - Fetches a list of public DNS resolvers from a community repository:
https://raw.githubusercontent.com/janmasarik/resolvers/master/resolvers.txt. - These are static text files used as data for the tool and do not involve executable code.
- [COMMAND_EXECUTION]: The skill provides numerous shell command examples and a Bash script for complex reconnaissance pipelines.
- Utilizes security tools such as
dnsx,subfinder, andhttpxto perform network-based DNS queries. - Includes standard Linux utilities like
cat,grep,awk, andsortfor data processing. - The provided Bash script ('Mega DNS Recon') automates a multi-step workflow involving directory creation, tool execution, and file output.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, creating a potential surface for indirect injection.
- Ingestion points: Reads hostnames, subdomains, and IP addresses from user-provided files (e.g.,
subs.txt,domains.txt). - Boundary markers: None identified in the provided command templates.
- Capability inventory: Performs network DNS resolution and writes results to files using the
-oand-jsonflags. - Sanitization: None specified; the skill relies on the underlying
dnsxtool to handle DNS record data safely.
Audit Metadata