skills/aeondave/malskill/wfuzz/Gen Agent Trust Hub

wfuzz

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a documentation and usage guide for wfuzz, an established open-source security tool for web application fuzzing. It does not contain any executable scripts or hidden commands.- [INDIRECT_PROMPT_INJECTION]: The skill involves running a tool that processes external inputs (wordlists) and produces console output. While this provides a surface where untrusted data could interact with the agent's context, it is the primary intended purpose of the tool and no malicious exploitation is suggested.- [EXTERNAL_DOWNLOADS]: The skill mentions pip install wfuzz, which is the standard installation procedure for the official package on the Python Package Index (PyPI). References to external documentation point to legitimate and well-known project resources on GitHub and ReadTheDocs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — wfuzz