ffuf-web-fuzzing
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides installation instructions for the
ffufutility through well-known and standard channels including Go package management, Homebrew, and official GitHub releases from theffuf/ffufrepository. It also referencesSecListsfrom thedanielmiessler/SecListsrepository, which is a standard resource in the security community.- [COMMAND_EXECUTION]: The skill contains a wide array of command-line examples forffufto perform web fuzzing tasks. These are instructional templates intended for user execution within an authorized testing environment.- [INDIRECT_PROMPT_INJECTION]: The skill establishes a process for the agent to analyze results generated byffuf, which are derived from external target responses. This ingestion surface is mitigated by a mandatory confirmation gate requiring explicit user verification of authorization, target scope, and intended commands before any execution occurs. - [SAFE]: The skill demonstrates a strong security posture by including clear legal disclaimers, requiring authorized use, and providing specific instructions on rate limiting and auto-calibration to ensure testing is performed responsibly and avoids unintended service disruption.
Audit Metadata