web2-recon
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as certificate transparency logs, subdomain enumeration APIs, and web crawling results. 1. Ingestion points: Data entering through curl commands and specialized reconnaissance tools. 2. Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore instructions embedded within the processed data. 3. Capability inventory: The skill has extensive access to network operations, file system writing, and shell command execution. 4. Sanitization: Employs standard shell tools like jq and grep for basic filtering but lacks safety validation for content.
- [COMMAND_EXECUTION]: The skill orchestrates a complex workflow involving numerous third-party command-line security tools and shell scripts.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill performs automated updates for nuclei templates and installs the trufflehog3 package via pip from public registries.
Audit Metadata