tlsx-probe
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples for executing the
tlsx,subfinder, andnaabucommand-line utilities. These are reputable tools used for their intended purpose of network security auditing and asset discovery. - [EXTERNAL_DOWNLOADS]: The skill references the official GitHub repository for ProjectDiscovery's
tlsxtool. ProjectDiscovery is a well-recognized and trusted organization in the security tooling space. - [PROMPT_INJECTION]: The described methodology involves processing output from external, untrusted network targets (such as SSL certificate SAN fields or DNS records). This presents a surface for indirect prompt injection. 1. Ingestion points: Data returned by the
tlsxandsubfindercommands. 2. Boundary markers: The methodology does not specify markers to separate tool output from instructions. 3. Capability inventory: The skill enables the execution of network scanning and analysis tools. 4. Sanitization: No explicit validation or sanitization of the external data is mentioned in the instructions.
Audit Metadata