recon-a-domain-passively

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill coordinates a reconnaissance workflow that relies on data from untrusted external sources, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: External data is collected from sources including WHOIS history, DNS records, Certificate Transparency logs, and public code repositories (SKILL.md Steps 2, 3, 5, 6).
  • Boundary markers: The workflow lacks instructions for the agent to use delimiters or specific directives to ignore embedded instructions in the collected data.
  • Capability inventory: The skill orchestrates multiple specialized tools for analyzing and mapping external infrastructure.
  • Sanitization: No sanitization or validation processes are mentioned for the content retrieved from third-party datasets.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:53 AM
Security Audit — agent-trust-hub — recon-a-domain-passively