recon-dir-scan

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web servers through scanning tools. This data is untrusted and could potentially be used for indirect prompt injection if the agent interprets response content as instructions.
  • Ingestion points: 'scripts/ffuf_results_parser.py' and 'scripts/status_code_analyzer.py' process external tool output.
  • Boundary markers: Absent.
  • Capability inventory: Subprocess calls for scanning (triggered by 'SKILL.md' instructions) and database writes via 'StorageAPI' in 'scripts/dir_scan_storage.py'.
  • Sanitization: Absent.
  • [SAFE]: The skill's behavior is consistent with its stated purpose of security reconnaissance. It uses standard tools and provides clear authorization warnings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:52 AM
Security Audit — agent-trust-hub — recon-dir-scan