dalfox-xss

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a methodology guide for using DalFox, a reputable open-source security tool for XSS scanning.\n- [COMMAND_EXECUTION]: The skill provides examples of shell commands for running security tools (dalfox, katana, gau) and standard utilities (cat, grep, sort). These are documented for their intended use in vulnerability assessment and reconnaissance.\n- [EXTERNAL_DOWNLOADS]: References the official GitHub repository for DalFox (https://github.com/hahwul/dalfox), which is a well-known project in the security community.\n- [DATA_EXFILTRATION]: While the tool performs network requests to scan targets and supports Blind XSS callbacks, these are standard features of XSS scanners used for authorized security testing. No evidence of unauthorized data exfiltration or harvesting of sensitive local credentials was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 03:13 AM
Security Audit — agent-trust-hub — dalfox-xss