kiterunner
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or unauthorized access patterns were detected. The skill's functionality is consistent with its stated purpose of API enumeration.
- [EXTERNAL_DOWNLOADS]: References the Kiterunner binary from Assetnote's official GitHub repository, which is a well-known and reputable source in the security industry.
- [COMMAND_EXECUTION]: Documents standard usage of the Kiterunner tool via shell commands for scanning and replaying API requests.
- [DATA_EXFILTRATION]: Uses environment variable placeholders (e.g., $TOKEN) for authentication tokens, preventing the exposure of hardcoded credentials.
Audit Metadata