skills/aeondave/malskill/shodan/Gen Agent Trust Hub

shodan

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from Shodan's internet-wide scans, which may contain attacker-controlled content designed to influence agent behavior.
  • Ingestion points: Commands such as shodan search, shodan host, and shodan parse ingest service banners, HTML titles, and other metadata from the internet into the agent's context.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat data from Shodan as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill provides the agent with shell access to run network-capable tools (shodan, httpx).
  • Sanitization: No sanitization or validation of the fetched data is performed before it is presented to the agent.
  • [DYNAMIC_EXECUTION]: The skill includes instructions to generate and execute Python code dynamically.
  • Evidence: A python3 -c command is provided in references/search-filters.md to calculate mmh3 hashes of favicons.
  • Execution method: The code is executed directly via the Python interpreter from a string template.
  • [COMMAND_EXECUTION]: The skill functions by executing multiple command-line interface tools.
  • Evidence: Commands for shodan, httpx, and python3 are distributed throughout SKILL.md and the reference documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — shodan