skills/aeondave/malskill/gobuster/Gen Agent Trust Hub

gobuster

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides extensive templates and examples for executing the Gobuster CLI tool to perform various security enumeration tasks, including directory brute-forcing, DNS subdomain discovery, and S3 bucket enumeration.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes workflows where the agent processes and potentially acts upon data received from external servers during the enumeration process.
  • Ingestion points: The agent is instructed to read and parse the output of Gobuster, which includes paths, status codes, and DNS records from external targets (SKILL.md, references/wordlists.md).
  • Boundary markers: The instructions lack explicit delimiters to isolate untrusted tool output from the agent's internal logic.
  • Capability inventory: The skill utilizes the agent's shell tool to run Gobuster and chain its output into further commands (e.g., looping through discovered paths).
  • Sanitization: There is no evidence of sanitization or validation of the results received from external targets before they are used in subsequent commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — gobuster