recon-and-methodology
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains numerous command-line examples for standard security tools including nmap, masscan, subfinder, amass, ffuf, gobuster, feroxbuster, nuclei, and arjun. These are intended to be executed by the user or agent during a security assessment.
- [DATA_EXFILTRATION]: The skill lists sensitive file paths and endpoints as targets for reconnaissance, such as
.envfiles,.aws/credentials,.git/config, and various backup files (backup.sql,config.php.bak). The methodology involves searching for these leaks on a target server as part of a bug bounty program. - [EXTERNAL_DOWNLOADS]: The skill provides commands that fetch data from external services like
crt.sh,securitytrails.com, andgithub.comfor the purpose of passive reconnaissance. These are well-known services used in the security industry.
Audit Metadata