agency-penetration-tester
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a bash script (
recon.sh) that automates the execution of multiple external security tools includingsubfinder,amass,dnsx,httpx,naabu,whatweb,gowitness, andh8mail. It also includes network routing commands such assudo ip route addused during pivoting operations to access internal networks. - [EXTERNAL_DOWNLOADS]: The technical deliverables reference and require several third-party offensive security utilities such as
chisel,ligolo-ng, andh8mailfor their operation. - [PROMPT_INJECTION]: The skill adopts a specialized offensive persona; however, it incorporates explicit "Critical Rules" regarding engagement authorization, scope management, and ethical standards to ensure actions are performed legally and safely.
- [DATA_EXFILTRATION]: The skill methodology includes techniques for checking credential leaks via
h8mailand documents data exfiltration patterns as part of its core offensive security mission. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it is designed to ingest and process untrusted data from external network targets.
- Ingestion points: Data enters the agent's context through network responses captured by the
requestslibrary in the Python script and probing tools in the bash script. - Boundary markers: The instructions lack specific markers or delimiters to differentiate between target data and agent instructions when analyzing external responses.
- Capability inventory: The skill environment allows for shell command execution, file system interaction, and network connectivity.
- Sanitization: The provided scripts do not include mechanisms for filtering or sanitizing external content before it is processed by the agent.
Audit Metadata