recon-fingerprint
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/fingerprint_storage.pyperforms dynamic path injection to import theStorageAPImodule. It usessys.path.insertwith a path constructed at runtime based on the file's relative location to load code from a sibling skill directory (results-storage). - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by fetching HTTP headers, cookies, and page content from target URLs, which could be used to influence the agent's behavior.
- Ingestion points:
scripts/extract_headers.py,scripts/tech_matcher.py, andscripts/waf_detector.pyfetch and analyze data from external web responses. - Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to ignore potentially malicious commands embedded in the fetched content.
- Capability inventory: The skill possesses capabilities for network requests, shell command execution (via external tools), and local file/database storage.
- Sanitization: While the scripts use regular expressions for technology matching, they do not include robust sanitization to prevent an LLM from interpreting instructions contained within the analyzed web content.
- [EXTERNAL_DOWNLOADS]: The
SKILL.mdfile and various guides within the skill provide instructions for the user to download and install several third-party security tools from external sources, includinggithub.com/projectdiscovery/httpx,github.com/projectdiscovery/nuclei,github.com/praetorian-inc/fingerprintx, andwafw00fvia Python's package registry. - [COMMAND_EXECUTION]: The skill relies extensively on executing external command-line tools such as
curl,whatweb,nmap,wafw00f,nuclei, andhttpxto perform its primary fingerprinting functions.
Audit Metadata