skills/aeondave/malskill/gau/Gen Agent Trust Hub

gau

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external passive URL providers which are considered untrusted sources.
  • Ingestion points: The gau tool fetches lists of URLs from Wayback Machine, Common Crawl, URLScan.io, and AlienVault OTX as described in SKILL.md and references/sources.md.
  • Boundary markers: The instructions lack explicit boundary markers or instructions to ignore malicious payloads embedded within the fetched URLs.
  • Capability inventory: The skill uses extensive shell pipelines, file writing (e.g., > urls.json, > params.txt), and network-active tools like httpx, nuclei, and ffuf across multiple examples.
  • Sanitization: Processing relies on grep, sed, and basic Python parsing which may not be robust against specifically crafted malicious data.
  • [DYNAMIC_EXECUTION]: The skill utilizes python3 -c to execute inline Python scripts for parsing URL parameters.
  • Evidence: Examples in SKILL.md and references/sources.md show the use of python3 -c to process data from sys.stdin.
  • [COMMAND_EXECUTION]: The skill relies heavily on external command-line tools and shell piping to perform its reconnaissance tasks.
  • Evidence: Commands include gau, httpx, nuclei, ffuf, hakrawler, katana, grep, sed, sort, uniq, wc, tr, and jq.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — gau