Red Team Tools and Methodology

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines workflows that rely on the execution of numerous external command-line tools such as amass, subfinder, nuclei, ffuf, and dalfox. These tools perform active network probing, DNS enumeration, and HTTP fuzzing.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements data pipelines that ingest content from untrusted external sources and process it through subsequent tools.
  • Ingestion points: External data is retrieved via curl (from bgp.he.net), waybackurls (Wayback Machine), and various subdomain enumeration tools (amass, subfinder, gau).
  • Boundary markers: There are no boundary markers or specific instructions to the agent to disregard potentially malicious instructions embedded in the retrieved data.
  • Capability inventory: The skill environment includes extensive network capabilities and file system access (creating directories, writing scan results, and generating reports).
  • Sanitization: The skill does not include steps to sanitize or validate external tool outputs before they are passed into further automation steps.
  • [DYNAMIC_EXECUTION]: The skill provides a complete bash script template (recon.sh) in section 10, which is intended to be generated and executed to automate the entire reconnaissance lifecycle.
  • [EXTERNAL_DOWNLOADS]: The instructions reference the installation of third-party security tools via package managers (e.g., go install, pip), which involves fetching and executing code from external repositories and registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — Red Team Tools and Methodology