skills/aeondave/malskill/massdns/Gen Agent Trust Hub

massdns

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches source code and resolver lists from public GitHub repositories, including the official massdns repository and community-maintained resolver sets. These are standard resources used for network reconnaissance and security auditing.
  • [REMOTE_CODE_EXECUTION]: Provides instructions to compile massdns from source using make and install the puredns wrapper via go install. These are standard installation methods for the documented tools.
  • [COMMAND_EXECUTION]: Employs standard Unix utilities such as grep, awk, and sed, along with specialized security tools like subfinder and httpx, to automate DNS resolution and result processing.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external lists of subdomains and resolvers, which constitutes an attack surface. 1. Ingestion points: subdomains.txt, resolvers.txt (SKILL.md); wordlist.txt (references/resolvers.md). 2. Boundary markers: Not explicitly defined in the provided examples. 3. Capability inventory: make, go install, and various shell-based data processing commands. 4. Sanitization: Relies on the default behavior of command-line utilities; no custom sanitization logic is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — massdns