Shodan Reconnaissance and Pentesting
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell commands for using the Shodan CLI tool, including installation (
pip install shodan), initialization (shodan init), and performing active scans (shodan scan submit). - [PRIVILEGE_ESCALATION]: The guide includes instructions to use
sudofor installing the Shodan package on specific operating systems, such as Arch Linux (sudo pacman -S python-shodan). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and parse data from external sources via Shodan (e.g., service banners, HTTP HTML content, and page titles). This content is controlled by external third parties and could be used to deliver malicious instructions to the agent.
- Ingestion points: Data enters the agent context through commands like
shodan search,shodan host,shodan download, andshodan parseinSKILL.md. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the retrieved data as untrusted or to ignore embedded instructions.
- Capability inventory: The skill possesses capabilities for shell command execution (
shodanCLI) and Python script execution as shown in the examples inSKILL.md. - Sanitization: No sanitization, filtering, or validation mechanisms for the retrieved service data are described in the core workflow.
Audit Metadata