recon-technique

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for the agent to install and execute third-party packages and scripts from sources that are not on the trusted vendor list.
  • Evidence: Mentions pip install s3scanner for S3 bucket enumeration in references/cloud-recon.md.
  • Evidence: Mentions python cloud_enum.py for multi-cloud discovery in references/cloud-recon.md.
  • Evidence: Mentions go install for the gotator permutation generator and pip install altdns in references/active-recon.md.
  • [REMOTE_CODE_EXECUTION]: Instructions to download and install external packages (pip install, go install) allow for the execution of unverified code within the agent's environment.
  • [INDIRECT_PROMPT_INJECTION]: The reconnaissance workflow involves gathering and processing large volumes of untrusted data from external sources which could contain malicious instructions.
  • Ingestion points: The agent reads tool outputs from resolved.txt, httpx_results.json, js_endpoints.txt, and historical URL archives in references/active-recon.md and references/passive-recon.md.
  • Capability inventory: The skill utilizes a wide array of shell-based network and file system tools (e.g., nmap, masscan, feroxbuster) across all phase-specific reference files.
  • Boundary markers: None present. The instructions do not specify any delimiters or warnings to ignore embedded instructions within the processed reconnaissance data.
  • Sanitization: None present. There is no logic provided to sanitize or validate the external data (such as web page titles or DNS TXT records) before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — recon-technique