recon-subdomain-enum

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a process that ingests data from external, untrusted sources such as Certificate Transparency (CT) logs, search engines, and PassiveDNS via external tools.
  • Ingestion points: Output from subfinder and amass (subdomain lists) processed in subsequent steps (SKILL.md).
  • Boundary markers: None explicitly mentioned in the instructions to prevent the agent from interpreting fetched hostnames as instructions.
  • Capability inventory: Executes network-probing commands via httpx, dnsx, and naabu (SKILL.md).
  • Sanitization: None documented; the skill relies on the listed tools to parse the data correctly.
  • [COMMAND_EXECUTION]: The skill provides specific command-line strings for various external security utilities (subfinder, amass, dnsx, httpx, naabu) to perform network reconnaissance. These operations are within the stated purpose of the skill for bug-bounty and security assessments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — recon-subdomain-enum