recon-and-methodology
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from various external sources and tools, creating a vulnerability surface where malicious content from a target could influence the agent's behavior.\n
- Ingestion points: The skill reads data from files generated by external tools such as 'subdomains.txt', 'live_hosts.txt', 'all_urls.txt', and 'nuclei-results.txt'.\n
- Boundary markers: There are no instructions for the agent to use delimiters or ignore embedded instructions when processing these tool outputs.\n
- Capability inventory: The skill utilizes powerful command-line tools including 'curl', 'nmap', 'nuclei', and 'ffuf' which can interact with network resources and the local file system.\n
- Sanitization: No explicit sanitization or validation of the tool outputs is mentioned before they are used in subsequent commands.\n- [COMMAND_EXECUTION]: The skill provides numerous shell commands for reconnaissance, port scanning, and vulnerability testing. While appropriate for the stated purpose of a bug bounty playbook, these commands allow the agent to perform extensive network and system operations.
Audit Metadata