feroxbuster
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and command templates for using feroxbuster, a legitimate tool for web content discovery in security auditing contexts.
- [COMMAND_EXECUTION]: The skill instructs the agent on how to use CLI commands for feroxbuster. The usage is restricted to scanning defined targets and emphasizes recursion limits and rate-limiting to prevent application degradation.
- [CREDENTIALS_UNSAFE]: While the command syntax includes an 'Authorization' header example, it uses a generic placeholder '' rather than any hardcoded secrets, which is a safe practice for documentation.
- [INDIRECT_PROMPT_INJECTION]: The skill involves scanning external web targets, which constitutes an ingestion surface. However, the tool's primary function is to report status codes and file existence rather than interpreting or executing the content of discovered files, posing no significant risk of command injection through external data.
Audit Metadata