passive-recon
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocessfor system-level operations, which is common in reconnaissance tools but requires careful monitoring when processing user-provided domain names. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to several well-known and reputable third-party services including crt.sh, HackerTarget, SecurityTrails, ViewDNS, CIRCL, and the Wayback Machine for data retrieval. All identified services are established resources in the security research community.
- [SAFE]: The code correctly identifies that certain operations (like SecurityTrails API) require an API key and instructs the user to provide one rather than hardcoding credentials.
- [SAFE]: The primary function of the skill is intelligence gathering through public archives and third-party APIs, specifically avoiding direct contact with target infrastructure as stated in its guidelines.
Audit Metadata