gau
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external passive URL providers which are considered untrusted sources.
- Ingestion points: The gau tool fetches lists of URLs from Wayback Machine, Common Crawl, URLScan.io, and AlienVault OTX as described in SKILL.md and references/sources.md.
- Boundary markers: The instructions lack explicit boundary markers or instructions to ignore malicious payloads embedded within the fetched URLs.
- Capability inventory: The skill uses extensive shell pipelines, file writing (e.g., > urls.json, > params.txt), and network-active tools like httpx, nuclei, and ffuf across multiple examples.
- Sanitization: Processing relies on grep, sed, and basic Python parsing which may not be robust against specifically crafted malicious data.
- [DYNAMIC_EXECUTION]: The skill utilizes python3 -c to execute inline Python scripts for parsing URL parameters.
- Evidence: Examples in SKILL.md and references/sources.md show the use of python3 -c to process data from sys.stdin.
- [COMMAND_EXECUTION]: The skill relies heavily on external command-line tools and shell piping to perform its reconnaissance tasks.
- Evidence: Commands include gau, httpx, nuclei, ffuf, hakrawler, katana, grep, sed, sort, uniq, wc, tr, and jq.
Audit Metadata