skills/aeondave/malskill/dnsx/Gen Agent Trust Hub

dnsx

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download wordlists and DNS resolver configurations from external sources.
  • Fetches a subdomain wordlist from Assetnote's GitHub repository: https://raw.githubusercontent.com/assetnote/commonspeak2-wordlists/master/subdomains/subdomains.txt.
  • Fetches a list of public DNS resolvers from a community repository: https://raw.githubusercontent.com/janmasarik/resolvers/master/resolvers.txt.
  • These are static text files used as data for the tool and do not involve executable code.
  • [COMMAND_EXECUTION]: The skill provides numerous shell command examples and a Bash script for complex reconnaissance pipelines.
  • Utilizes security tools such as dnsx, subfinder, and httpx to perform network-based DNS queries.
  • Includes standard Linux utilities like cat, grep, awk, and sort for data processing.
  • The provided Bash script ('Mega DNS Recon') automates a multi-step workflow involving directory creation, tool execution, and file output.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, creating a potential surface for indirect injection.
  • Ingestion points: Reads hostnames, subdomains, and IP addresses from user-provided files (e.g., subs.txt, domains.txt).
  • Boundary markers: None identified in the provided command templates.
  • Capability inventory: Performs network DNS resolution and writes results to files using the -o and -json flags.
  • Sanitization: None specified; the skill relies on the underlying dnsx tool to handle DNS record data safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — dnsx