subdomain-takeover-hunt
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill uses standard command-line tools for security reconnaissance and does not exhibit any malicious behaviors such as credential exfiltration, obfuscation, or unauthorized remote code execution.
- [PROMPT_INJECTION]: The skill processes a list of subdomains from an external file (
alive_subs.txt) and passes them to shell tools likecurlandsubjack. While this presents a theoretical attack surface for indirect injection via malicious domain names, it is a standard workflow for security reconnaissance tools and is considered low risk in this context. - Ingestion points:
alive_subs.txt(SKILL.md) - Boundary markers: None
- Capability inventory: Shell execution of
dnsx,subzy,subjack,nuclei,curl,dig(SKILL.md) - Sanitization: None
Audit Metadata