wfuzz
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a documentation and usage guide for
wfuzz, an established open-source security tool for web application fuzzing. It does not contain any executable scripts or hidden commands.- [INDIRECT_PROMPT_INJECTION]: The skill involves running a tool that processes external inputs (wordlists) and produces console output. While this provides a surface where untrusted data could interact with the agent's context, it is the primary intended purpose of the tool and no malicious exploitation is suggested.- [EXTERNAL_DOWNLOADS]: The skill mentionspip install wfuzz, which is the standard installation procedure for the official package on the Python Package Index (PyPI). References to external documentation point to legitimate and well-known project resources on GitHub and ReadTheDocs.
Audit Metadata