recon-a-domain-passively

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and does not contain executable code, script blocks, or command-line instructions that would be automatically executed by the agent.- [SAFE]: The metadata includes disable-model-invocation: true, which restricts the execution environment and ensures the model does not autonomously invoke tools based on these instructions.- [SAFE]: The workflow involves processing external data (such as WHOIS records, DNS data, and web archives), which technically introduces an indirect prompt injection surface. * Ingestion points: External data is collected from WHOIS, DNS, web archives, and Git history (Steps 2, 3, 5, 6). * Boundary markers: The skill references an ethics guide and defines a 'passive boundary', though it lacks specific technical delimiters for the fetched content. * Capability inventory: The skill coordinates various recon tools like who-owns-this-domain and find-hidden-subdomains. * Sanitization: No explicit sanitization or filtering of external content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 03:40 PM
Security Audit — agent-trust-hub — recon-a-domain-passively