skills/timsonner/agent-skills/ffuf/Gen Agent Trust Hub

ffuf

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides several command examples for the ffuf utility to be used in shell environments. These commands are tailored for web endpoint discovery and API fuzzing during authorized security assessments.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines procedures for interacting with external web servers, which involves ingesting untrusted data in the form of HTTP responses. This represents a potential indirect prompt injection surface for an agent interpreting these results.
  • Ingestion points: HTTP responses captured by ffuf commands in SKILL.md.
  • Boundary markers: No specific delimiters or warnings for the agent to ignore instructions within the tool's output are included.
  • Capability inventory: Execution of the ffuf binary via the shell.
  • Sanitization: The skill provides commands for data acquisition but does not include logic for sanitizing the resulting output before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:39 AM
Security Audit — agent-trust-hub — ffuf