web-enumeration

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides scripts for security reconnaissance, such as scanning for .env files, .git directories, and identifying Varnish cache headers. These are standard techniques used in authorized web security auditing.
  • [COMMAND_EXECUTION]: The skill documents the use of standard security tools like curl, grep, paramspider, arjun, and x8-cli. These are legitimate command-line utilities for security professionals.
  • [DATA_EXFILTRATION]: While the skill contains patterns for extracting sensitive data (like database credentials from .env files), these actions are described within the context of security testing to identify and remediate vulnerabilities, rather than exfiltrating data to an unauthorized third party.
  • [REMOTE_CODE_EXECUTION]: The skill mentions a third-party tool, git-dumper, via a GitHub reference. This reference is used to illustrate how to recover a git repository from an exposed directory, which is a common security testing procedure.
  • [PROMPT_INJECTION]: No evidence of prompt injection or attempts to override AI safety guidelines were found in the skill content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — web-enumeration