domain-hunter
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill provides instructions for the agent to extract
SPACESHIP_API_KEYandSPACESHIP_API_SECRETdirectly from the user's shell configuration file (~/.zshrc). This behavior exposes sensitive long-term credentials to the agent context. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external social platforms like Twitter and Reddit to find promo codes. It does not use boundary markers or sanitization to handle this content, creating a surface where malicious social media posts could attempt to influence the agent's behavior. Ingestion points: Twitter and Reddit search results retrieved via external scripts. Boundary markers: Absent. Capability inventory: Shell execution (whois, curl), sensitive file access (~/.zshrc), and network operations. Sanitization: Absent.
- [COMMAND_EXECUTION]: The skill utilizes various shell commands to perform its core functions, including extracting secrets from system files, checking domain availability via
whois, and making authenticated network requests to the Spaceship API usingcurl.
Audit Metadata