red-team-tools

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands for automating security reconnaissance and vulnerability testing. Tools utilized include Amass, Subfinder, Nuclei, ffuf, and Dalfox. These operations are within the scope of the skill's intended use for red-teaming and bug bounty hunting.
  • [EXTERNAL_DOWNLOADS]: Fetches reconnaissance data and historical URLs from external services like the Wayback Machine and bgp.he.net using standard utility commands (curl, waybackurls, gau).
  • [PROMPT_INJECTION]: The skill processes untrusted data from external domains (Ingestion point: SKILL.md tool workflows) using high-capability tools like bash, nuclei, and dalfox (Capability inventory). While no explicit boundary markers or sanitization logic is provided in the instruction set, the risk of indirect prompt injection is inherent to the primary purpose of security research and analysis of external systems.
  • [SAFE]: No malicious patterns such as credential theft, code obfuscation, or unauthorized persistence mechanisms were detected. The skill's behavior is consistent with its stated purpose of providing a red-team toolkit for authorized security assessments.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 05:06 PM
Security Audit — agent-trust-hub — red-team-tools