skills/uphiago/recon-skills/hunt-grpc/Gen Agent Trust Hub

hunt-grpc

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains various shell commands for network reconnaissance and gRPC service interaction. It utilizes standard tools like nmap for port discovery, openssl for protocol negotiation checks, and curl for HTTP/2 probing.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing security auditing tools. It suggests using brew or go install to obtain grpcurl from its official repository and git clone to fetch the rapidresetclient utility for authorized denial-of-service testing. These are standard procedures for security auditing tasks.
  • [PROMPT_INJECTION]: The 'Verification' section contains instructions for the agent to validate the presence of specific metadata and headers within the SKILL.md file using grep. While these are self-referential instructions, they are used for environment validation rather than malicious behavior override.
  • [DATA_EXFILTRATION]: All network operations (e.g., curl, grpcurl) are directed towards a user-specified $TARGET variable for the purpose of security testing. There is no evidence of commands designed to harvest or exfiltrate sensitive local data to unauthorized external endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — hunt-grpc