recon-arsenal

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines a large collection of shell command templates for common networking and security tools (e.g., nmap, rustscan, masscan, ffuf) to be executed by the agent.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of data from external network targets, such as service banners and HTTP headers, which represents a known attack surface for indirect prompt injection.\n
  • Ingestion points: Data returned from network probes using tools like curl, snmpwalk, and nmap (SKILL.md).\n
  • Boundary markers: The instructions do not define explicit delimiters or instructions to ignore potential commands embedded in target responses.\n
  • Capability inventory: The agent is granted the capability to execute a wide array of shell-based reconnaissance tools (SKILL.md).\n
  • Sanitization: The skill suggests some tool-level filtering (e.g., ffuf's -fs flag), but lacks specific sanitization for the resulting data before it enters the agent's context.\n- [PRIVILEGE_ESCALATION]: The documentation includes steps that require elevated permissions on a standard Linux environment, specifically modifying the /etc/hosts file and using the mount command for NFS exports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:01 PM
Security Audit — agent-trust-hub — recon-arsenal