subdomain-takeover

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is a documentation-only resource. It contains instructions, tables, and methodology for security analysis but does not ship with any executable scripts, binaries, or configuration files.
  • [PROMPT_INJECTION]: The skill's methodology involves the ingestion of untrusted external data, creating a surface for indirect prompt injection.
  • Ingestion points: DNS record values (CNAME, NS, MX) and HTTP response bodies/headers are retrieved from target domains (Section 2, Section 8).
  • Boundary markers: Absent. There are no instructions provided to the agent to use delimiters or ignore embedded instructions when processing external tool output.
  • Capability inventory: The playbook directs the agent to execute shell commands using tools like dig, curl, and various cloud CLIs (aws, heroku) based on the analyzed data (Section 4, Section 5).
  • Sanitization: Absent. The skill does not include steps for the agent to sanitize or validate external content before it is processed as part of the operational logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — subdomain-takeover