gobuster
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides extensive templates and examples for executing the Gobuster CLI tool to perform various security enumeration tasks, including directory brute-forcing, DNS subdomain discovery, and S3 bucket enumeration.
- [INDIRECT_PROMPT_INJECTION]: The skill describes workflows where the agent processes and potentially acts upon data received from external servers during the enumeration process.
- Ingestion points: The agent is instructed to read and parse the output of Gobuster, which includes paths, status codes, and DNS records from external targets (SKILL.md, references/wordlists.md).
- Boundary markers: The instructions lack explicit delimiters to isolate untrusted tool output from the agent's internal logic.
- Capability inventory: The skill utilizes the agent's shell tool to run Gobuster and chain its output into further commands (e.g., looping through discovered paths).
- Sanitization: There is no evidence of sanitization or validation of the results received from external targets before they are used in subsequent commands.
Audit Metadata