recon-scope-triage
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell command examples using
curlandcmpto identify 'soft-404' false positives. This involves executing commands on the local system to compare HTTP responses from remote hosts. - [PROMPT_INJECTION]: The skill outlines specific logic for the agent to follow regarding asset ownership, such as the 'guilty-until-proven' rule. These instructions define task-specific behavior for an authorized engagement and do not attempt to bypass underlying safety guidelines.
- [PROMPT_INJECTION]: The skill defines a workflow for processing external reconnaissance data (ASM reports, cloud bucket lists) which constitutes an indirect prompt injection surface. Ingestion points: Untrusted reconnaissance datasets and exports as mentioned in SKILL.md. Boundary markers: Absent; data is processed as part of the triage workflow without explicit delimiters. Capability inventory: Uses
curlandcmpfor network and file operations. Sanitization: There is no mention of sanitizing or validating domain names or URLs before they are used in diagnostic commands.
Audit Metadata