recon-carwashes

Fail

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill fetches data from crt.sh and pipes it directly into the Python interpreter (python3 -c). This pattern allows remote content to execute code locally, posing a risk if the remote service is compromised or the response is intercepted.
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands for automated scanning, including curl-based loops that execute against target domains and their filesystems.
  • [DATA_EXFILTRATION]: The instructions include specific grep patterns designed to identify and extract sensitive personally identifiable information (PII) such as emails, phone numbers, addresses, license plates, and payment card details from publicly accessible log files.
Recommendations
  • HIGH: Downloads and executes remote code from: https://crt.sh/?q=%25.$TARGET&output=json - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 9, 2026, 05:19 PM
Security Audit — agent-trust-hub — recon-carwashes