implementing-zero-trust-dns-with-nextdns

Fail

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and execute an installation script directly from the official NextDNS domain (nextdns.io). This is the standard deployment method for the service.
  • [COMMAND_EXECUTION]: The provided documentation and scripts utilize sudo for modifying system-level DNS configurations (e.g., systemd-resolved) and for installing the local NextDNS CLI agent, which is expected for administrative networking tasks.
  • [DATA_EXFILTRATION]: The scripts interact with the NextDNS API (api.nextdns.io) to fetch configuration settings and query logs. This process is authenticated via a user-provided API key passed as a command-line argument, following standard practices for CLI security tools.
  • [PROMPT_INJECTION]: Analysis of the instructional content and example data samples shows no attempts to override agent behavior or bypass safety filters.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 16, 2026, 09:08 AM
Security Audit — agent-trust-hub — implementing-zero-trust-dns-with-nextdns