web2-recon

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as certificate transparency logs, subdomain enumeration APIs, and web crawling results. 1. Ingestion points: Data entering through curl commands and specialized reconnaissance tools. 2. Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore instructions embedded within the processed data. 3. Capability inventory: The skill has extensive access to network operations, file system writing, and shell command execution. 4. Sanitization: Employs standard shell tools like jq and grep for basic filtering but lacks safety validation for content.
  • [COMMAND_EXECUTION]: The skill orchestrates a complex workflow involving numerous third-party command-line security tools and shell scripts.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill performs automated updates for nuclei templates and installs the trufflehog3 package via pip from public registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:02 PM
Security Audit — agent-trust-hub — web2-recon