ksubdomain-brute

Fail

Audited by Snyk on Jun 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 1.00). This is a personal GitHub repository for a root-run subdomain brute-forcing tool from an unvetted user ("boy-hack") that may distribute prebuilt executables or instruct running code as root, which is a common vector for malware—treat as suspicious unless vetted and code/release artifacts are audited.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt repeatedly instructs running ksubdomain with sudo and explicitly states it requires root privileges, which encourages the agent to obtain elevated access and perform actions that can change the host system's state.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 16, 2026, 03:13 AM
Issues
2
Security Audit — snyk — ksubdomain-brute