recon-content-discovery

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides educational content and best practices for web endpoint discovery and parameter mining.
  • [NO_CODE]: No executable scripts or source code files are included with this skill; it consists entirely of documentation and configuration metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions facilitate processing of external web targets. While this presents a surface for processing untrusted data, the methodology is standard for the intended pentest and bug bounty use cases. 1. Ingestion points: User-provided target URLs (SKILL.md). 2. Boundary markers: None. 3. Capability inventory: Execution of gau, waybackurls, katana, gospider, feroxbuster, and arjun. 4. Sanitization: None; rely on tool-level input handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — recon-content-discovery