Back to skill

Security audit

domain-recon

Security checks across malware telemetry and agentic risk

Overview

This is a coherent passive reconnaissance skill, with disclosed third-party lookups and no evidence of credential access, persistence, or destructive behavior.

Install this only if you are comfortable sending the indicators you query to external public services such as crt.sh, certSpotter, RDAP providers, Google or Cloudflare DNS, ip-api.com, RIPEstat, and archive.org. Avoid using the HTTP-only IP and Wayback lookups for sensitive targets on untrusted networks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The documentation makes clear that queried domains, IPs, and URLs are sent to multiple third-party services, but it does not present an explicit privacy warning or consent boundary. In a reconnaissance context, those query terms may themselves be sensitive, revealing investigation targets, internal assets, or customer-related indicators to external providers and intermediaries.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The IP enrichment request is sent to ip-api.com over plain HTTP, so queried IP addresses and returned metadata can be observed or modified by any on-path network actor. In a recon tool, queried infrastructure targets may themselves be sensitive, so this weakens confidentiality and integrity of results even though no credentials are involved.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.