dns-pentesting
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to use various network diagnostic and security tools such as
nmap,dig,nslookup,dnsrecon,fierce,dnsenum, andmsfconsole. These tools are standard for the stated purpose of DNS service enumeration and vulnerability assessment.\n- [EXTERNAL_DOWNLOADS]: The skill utilizescurlto fetch information fromcrt.sh(a well-known certificate transparency log service). This is a common practice in passive information gathering during security assessments.\n- [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by ingesting and processing data from external DNS records.\n - Ingestion points: The agent parses results from DNS queries (e.g.,
dig TXT,dig ANY) targeting external servers inSKILL.mdandreferences/dns-techniques.md.\n - Boundary markers: Absent; there are no specific instructions or delimiters to isolate untrusted DNS record content from agent instructions.\n
- Capability inventory: The skill utilizes powerful tools across all scripts, including network scanners (
nmap), exploitation frameworks (msfconsole), and tunneling tools (iodine,dnscat2).\n - Sanitization: No explicit sanitization or filtering of the retrieved DNS record content is mentioned in the methodology.
Audit Metadata