recon-and-methodology

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from various external sources and tools, creating a vulnerability surface where malicious content from a target could influence the agent's behavior.\n
  • Ingestion points: The skill reads data from files generated by external tools such as 'subdomains.txt', 'live_hosts.txt', 'all_urls.txt', and 'nuclei-results.txt'.\n
  • Boundary markers: There are no instructions for the agent to use delimiters or ignore embedded instructions when processing these tool outputs.\n
  • Capability inventory: The skill utilizes powerful command-line tools including 'curl', 'nmap', 'nuclei', and 'ffuf' which can interact with network resources and the local file system.\n
  • Sanitization: No explicit sanitization or validation of the tool outputs is mentioned before they are used in subsequent commands.\n- [COMMAND_EXECUTION]: The skill provides numerous shell commands for reconnaissance, port scanning, and vulnerability testing. While appropriate for the stated purpose of a bug bounty playbook, these commands allow the agent to perform extensive network and system operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:47 AM
Security Audit — agent-trust-hub — recon-and-methodology