recon-technique
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for the agent to install and execute third-party packages and scripts from sources that are not on the trusted vendor list.
- Evidence: Mentions
pip install s3scannerfor S3 bucket enumeration inreferences/cloud-recon.md. - Evidence: Mentions
python cloud_enum.pyfor multi-cloud discovery inreferences/cloud-recon.md. - Evidence: Mentions
go installfor thegotatorpermutation generator andpip install altdnsinreferences/active-recon.md. - [REMOTE_CODE_EXECUTION]: Instructions to download and install external packages (
pip install,go install) allow for the execution of unverified code within the agent's environment. - [INDIRECT_PROMPT_INJECTION]: The reconnaissance workflow involves gathering and processing large volumes of untrusted data from external sources which could contain malicious instructions.
- Ingestion points: The agent reads tool outputs from
resolved.txt,httpx_results.json,js_endpoints.txt, and historical URL archives inreferences/active-recon.mdandreferences/passive-recon.md. - Capability inventory: The skill utilizes a wide array of shell-based network and file system tools (e.g.,
nmap,masscan,feroxbuster) across all phase-specific reference files. - Boundary markers: None present. The instructions do not specify any delimiters or warnings to ignore embedded instructions within the processed reconnaissance data.
- Sanitization: None present. There is no logic provided to sanitize or validate the external data (such as web page titles or DNS TXT records) before it is processed by the agent.
Audit Metadata