shodan-reconnaissance
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for installing the Shodan CLI using package managers such as pip and pacman. It includes numerous examples of shell commands for querying host information, searching for exposed services, and parsing data. These commands are standard for the intended use of the Shodan tool.
- [EXTERNAL_DOWNLOADS]: The skill interacts with the well-known Shodan API (api.shodan.io) to fetch host data and search results. These interactions are legitimate for a reconnaissance skill and target an established service.
- [SAFE]: No malicious patterns were detected. The skill uses placeholders for API keys, lacks obfuscation, and does not contain any persistence or exfiltration mechanisms. The documented reconnaissance activities are passive and utilize a trusted industry-standard platform.
Audit Metadata