theharvester
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and example commands for 'theHarvester', a legitimate and widely-used tool for passive reconnaissance. All examples use the standard documentation domain 'contoso.com' and focus on public source gathering (Google, Bing, Shodan).
- [INDIRECT_PROMPT_INJECTION]: The skill involves processing data from external, untrusted sources (OSINT results from search engines). While this represents a potential attack surface for indirect prompt injection, it is the primary intended function of the tool and the instructions focus on manual-like guidance rather than automated dangerous capabilities. Ingestion points: Output from 'theHarvester' commands executed against external domains. Boundary markers: Absent. Capability inventory: The skill instructions focus on recording leads and guiding future validation; no automated dangerous operations (e.g., file writes, code execution) are defined. Sanitization: Absent.
Audit Metadata