web-enumeration
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides scripts for security reconnaissance, such as scanning for
.envfiles,.gitdirectories, and identifying Varnish cache headers. These are standard techniques used in authorized web security auditing. - [COMMAND_EXECUTION]: The skill documents the use of standard security tools like
curl,grep,paramspider,arjun, andx8-cli. These are legitimate command-line utilities for security professionals. - [DATA_EXFILTRATION]: While the skill contains patterns for extracting sensitive data (like database credentials from
.envfiles), these actions are described within the context of security testing to identify and remediate vulnerabilities, rather than exfiltrating data to an unauthorized third party. - [REMOTE_CODE_EXECUTION]: The skill mentions a third-party tool,
git-dumper, via a GitHub reference. This reference is used to illustrate how to recover a git repository from an exposed directory, which is a common security testing procedure. - [PROMPT_INJECTION]: No evidence of prompt injection or attempts to override AI safety guidelines were found in the skill content.
Audit Metadata