hakrawler
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
hakrawlertool from an external GitHub repository (github.com/hakluke/hakrawler). While this is a common utility for security research, the source is not verified as a trusted vendor. - [COMMAND_EXECUTION]: The skill makes extensive use of complex shell pipelines to automate security scanning workflows. These pipelines utilize tools like
xargs,grep,jq, and shellwhileloops to process the output of network-connected commands. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large volumes of untrusted data from the web (URLs, endpoints, and JavaScript file contents). This presents an indirect injection surface where malicious content on a target website could potentially influence the behavior of the processing scripts.
- Ingestion points: Data enters the system via
hakrawlercrawl results andcurlrequests to external JavaScript files. - Boundary markers: None detected; the pipelines treat tool output as standard input for subsequent commands without explicit sanitization of shell metacharacters.
- Capability inventory: The skill possesses network capabilities (
curl,httpx,subfinder), file system write capabilities (tee,>), and execution capabilities via shell piping. - Sanitization: The skill relies on
grepandjqfor filtering, but these may not prevent sophisticated command injection payloads embedded within crawled URLs or response bodies.
Audit Metadata