Shodan Reconnaissance and Pentesting

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands for using the Shodan CLI tool, including installation (pip install shodan), initialization (shodan init), and performing active scans (shodan scan submit).
  • [PRIVILEGE_ESCALATION]: The guide includes instructions to use sudo for installing the Shodan package on specific operating systems, such as Arch Linux (sudo pacman -S python-shodan).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and parse data from external sources via Shodan (e.g., service banners, HTTP HTML content, and page titles). This content is controlled by external third parties and could be used to deliver malicious instructions to the agent.
  • Ingestion points: Data enters the agent context through commands like shodan search, shodan host, shodan download, and shodan parse in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the retrieved data as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill possesses capabilities for shell command execution (shodan CLI) and Python script execution as shown in the examples in SKILL.md.
  • Sanitization: No sanitization, filtering, or validation mechanisms for the retrieved service data are described in the core workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — Shodan Reconnaissance and Pentesting