ffuf-web-fuzzing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the ffuf utility from its official GitHub repository and recommends wordlists from the well-known SecLists project. These are standard resources for security professionals.\n- [COMMAND_EXECUTION]: The skill contains various shell command templates for directory discovery, subdomain enumeration, and parameter fuzzing. To mitigate misuse, the skill mandates a strict 'confirmation gate' requiring the agent to obtain target information, verify authorization, and explain commands before execution.\n- [PROMPT_INJECTION]: The skill processes untrusted external data such as raw HTTP requests and web server responses. While this creates a surface for indirect prompt injection, the skill specifically instructs the agent to remain read-only and provide defensive guidance until explicit user confirmation is received.\n- [NO_CODE]: Several supplementary files, including a Python analysis script (ffuf_helper.py) and additional documentation, are referenced in the instructions but are not present in the provided skill bundle. This is an inconsistency in documentation rather than a safety risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 09:43 AM
Security Audit — agent-trust-hub — ffuf-web-fuzzing