spiderfoot
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to clone the SpiderFoot repository from GitHub (
https://github.com/smicallef/spiderfoot) and install dependencies from a requirements file. This is standard procedure for using this open-source tool. - [COMMAND_EXECUTION]: The documentation contains numerous shell commands for running the tool, including starting a web UI (
python3 sf.py -l 127.0.0.1:5001) and executing CLI scans. It also provides a Python automation script usingsubprocess.run()to execute the tool programmatically. These are documented usage patterns for the tool's primary function. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it is designed to ingest and process large amounts of untrusted data from external sources (DNS, social media, web crawlers, breach data).
- Ingestion points: Data enters the context via the
sf.pyoutput (JSON/CSV) which is then processed by Python scripts described inSKILL.mdandreferences/modules.md. - Boundary markers: None identified in the provided scripts or instructions.
- Capability inventory: The skill uses
subprocess.run()to execute shell commands andopen()/write()for file operations. - Sanitization: The provided Python snippets perform basic JSON parsing and filtering but do not include explicit sanitization or escaping of the harvested data before potential further use.
- [DATA_EXPOSURE]: The documentation mentions high-value API keys for services like Shodan, VirusTotal, and HaveIBeenPwned. It correctly advises configuring these through the Web UI or settings file, which is a standard practice for this tool and does not involve hardcoded secrets in the skill itself.
Audit Metadata