recon-bakeries
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard command-line utilities including
curl,jq,grep, andsortto perform its intended reconnaissance tasks against target domains. - [EXTERNAL_DOWNLOADS]: Employs
curlto communicate with target web servers to perform platform fingerprinting and test the accessibility of specific e-commerce API endpoints. - [PROMPT_INJECTION]: The skill ingests untrusted data from target web responses via
curl(SKILL.md) and processes it with local tools. While it lacks explicit boundary markers or sanitization, this vulnerability surface is characteristic of web reconnaissance tools and represents a low risk in this context.
Audit Metadata