domains-dns

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional, providing recipes for standard DNS records (A, CNAME, MX, TXT, CAA) and TLS automation using well-known tools like certbot and acme.sh.
  • [COMMAND_EXECUTION]: The skill includes a shell script scripts/verify.sh and various dig, openssl, and curl command snippets in SKILL.md. These commands are strictly for network diagnostics and information gathering. They do not modify the system state, escalate privileges, or interact with sensitive local files.
  • [EXTERNAL_DOWNLOADS]: The skill references standard ACME clients and platform-managed services (Vercel, Netlify, Cloudflare) for certificate management. No unverifiable third-party code is downloaded or executed.
  • [DATA_EXFILTRATION]: Network operations are limited to DNS queries and TLS handshakes to the domain being audited. There is no evidence of sensitive data being transmitted to external servers.
  • [PROMPT_INJECTION]: The evals/cases.yaml file defines expected routing behavior for an agent but does not contain instructions to bypass safety filters or override system constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — domains-dns