Red Team Tools and Methodology
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill defines workflows that rely on the execution of numerous external command-line tools such as
amass,subfinder,nuclei,ffuf, anddalfox. These tools perform active network probing, DNS enumeration, and HTTP fuzzing. - [INDIRECT_PROMPT_INJECTION]: The skill implements data pipelines that ingest content from untrusted external sources and process it through subsequent tools.
- Ingestion points: External data is retrieved via
curl(from bgp.he.net),waybackurls(Wayback Machine), and various subdomain enumeration tools (amass,subfinder,gau). - Boundary markers: There are no boundary markers or specific instructions to the agent to disregard potentially malicious instructions embedded in the retrieved data.
- Capability inventory: The skill environment includes extensive network capabilities and file system access (creating directories, writing scan results, and generating reports).
- Sanitization: The skill does not include steps to sanitize or validate external tool outputs before they are passed into further automation steps.
- [DYNAMIC_EXECUTION]: The skill provides a complete bash script template (
recon.sh) in section 10, which is intended to be generated and executed to automate the entire reconnaissance lifecycle. - [EXTERNAL_DOWNLOADS]: The instructions reference the installation of third-party security tools via package managers (e.g.,
go install,pip), which involves fetching and executing code from external repositories and registries.
Audit Metadata