Red Team Tools and Methodology

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Command Execution (MEDIUM): The skill defines a large set of shell commands and a complete bash script (recon.sh) for automating asset discovery and vulnerability scanning.
  • External Downloads (MEDIUM): The methodology relies on third-party security tools (Amass, Nuclei, Subfinder) that perform network queries and fetch external content like vulnerability templates or host metadata.
  • Data Exposure (LOW): The skill prerequisites require the user to provide API keys for services like Shodan and Censys, which are then used in the automated workflows.
  • Indirect Prompt Injection (LOW): The skill processes untrusted external data (historical URLs, subdomain lists, and HTTP response headers) through tools like waybackurls and httpx. There is a risk of ingestion of malicious instructions embedded in target data, though severity is low due to LLM guardrails. Evidence: Ingestion points include target response data; Capability inventory includes file-writing and network requests; Sanitization is limited to basic sorting and filtering.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 06:41 PM