dns-security

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill proactively addresses indirect prompt injection by including a dedicated safety notice that instructs the agent to treat all configuration content (such as TXT records and zone comments) as untrusted data and to ignore any instructions found within those fields.
  • [COMMAND_EXECUTION]: The skill utilizes standard analysis tools (Read, Grep, Glob) to search for DNS configuration files across various platforms including BIND, systemd, Kubernetes, and cloud providers (AWS, GCP, Azure). This behavior is limited to the skill's stated purpose of security assessment.
  • [DATA_EXFILTRATION]: No network communication or data exfiltration patterns were observed. The skill analyzes local or provided configuration data without attempting to send findings to external servers.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any external package installations or script downloads. All references target well-known standards bodies and security organizations (NIST, CIS, IANA, CISA, IETF).
  • [CREDENTIALS_UNSAFE]: While the skill scans for configuration files that may contain network topology information, it does not target or hardcode secrets, passwords, or API keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:11 PM
Security Audit — agent-trust-hub — dns-security