passive-recon
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and methodologies focus exclusively on passive reconnaissance, gathering data from external search engine APIs without direct interaction with target systems.
- [SAFE]: Communication is directed to well-known and established security services (FOFA, Quake, Hunter), which are legitimate tools for OSINT purposes.
- [SAFE]: The skill uses environment variables (e.g., ${FOFA_KEY}) for API authentication, adhering to secure credential management practices and avoiding hardcoded secrets.
- [SAFE]: No evidence of prompt injection, data exfiltration, or unauthorized command execution was found; the skill explicitly warns against active scanning or accessing targets directly.
Audit Metadata