shodan
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from Shodan's internet-wide scans, which may contain attacker-controlled content designed to influence agent behavior.
- Ingestion points: Commands such as
shodan search,shodan host, andshodan parseingest service banners, HTML titles, and other metadata from the internet into the agent's context. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat data from Shodan as untrusted or to ignore embedded instructions.
- Capability inventory: The skill provides the agent with shell access to run network-capable tools (
shodan,httpx). - Sanitization: No sanitization or validation of the fetched data is performed before it is presented to the agent.
- [DYNAMIC_EXECUTION]: The skill includes instructions to generate and execute Python code dynamically.
- Evidence: A
python3 -ccommand is provided inreferences/search-filters.mdto calculate mmh3 hashes of favicons. - Execution method: The code is executed directly via the Python interpreter from a string template.
- [COMMAND_EXECUTION]: The skill functions by executing multiple command-line interface tools.
- Evidence: Commands for
shodan,httpx, andpython3are distributed throughoutSKILL.mdand the reference documentation.
Audit Metadata