subdomain-takeover-hunt

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill uses standard command-line tools for security reconnaissance and does not exhibit any malicious behaviors such as credential exfiltration, obfuscation, or unauthorized remote code execution.
  • [PROMPT_INJECTION]: The skill processes a list of subdomains from an external file (alive_subs.txt) and passes them to shell tools like curl and subjack. While this presents a theoretical attack surface for indirect injection via malicious domain names, it is a standard workflow for security reconnaissance tools and is considered low risk in this context.
  • Ingestion points: alive_subs.txt (SKILL.md)
  • Boundary markers: None
  • Capability inventory: Shell execution of dnsx, subzy, subjack, nuclei, curl, dig (SKILL.md)
  • Sanitization: None
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — subdomain-takeover-hunt