ksubdomain-brute
Fail
Audited by Snyk on Jun 16, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 1.00). This is a personal GitHub repository for a root-run subdomain brute-forcing tool from an unvetted user ("boy-hack") that may distribute prebuilt executables or instruct running code as root, which is a common vector for malware—treat as suspicious unless vetted and code/release artifacts are audited.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt repeatedly instructs running ksubdomain with sudo and explicitly states it requires root privileges, which encourages the agent to obtain elevated access and perform actions that can change the host system's state.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata