subdomain-takeover
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill is a documentation-only resource. It contains instructions, tables, and methodology for security analysis but does not ship with any executable scripts, binaries, or configuration files.
- [PROMPT_INJECTION]: The skill's methodology involves the ingestion of untrusted external data, creating a surface for indirect prompt injection.
- Ingestion points: DNS record values (CNAME, NS, MX) and HTTP response bodies/headers are retrieved from target domains (Section 2, Section 8).
- Boundary markers: Absent. There are no instructions provided to the agent to use delimiters or ignore embedded instructions when processing external tool output.
- Capability inventory: The playbook directs the agent to execute shell commands using tools like
dig,curl, and various cloud CLIs (aws,heroku) based on the analyzed data (Section 4, Section 5). - Sanitization: Absent. The skill does not include steps for the agent to sanitize or validate external content before it is processed as part of the operational logic.
Audit Metadata