performing-csrf-attack-simulation
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for using
curlto interact with web application endpoints and utilizes Python'shttp.servermodule to host Proof-of-Concept files locally. - [EXTERNAL_DOWNLOADS]: References the third-party tool
xsrfprobeas an automated scanner for CSRF vulnerabilities. - [REMOTE_CODE_EXECUTION]: Includes HTML and JavaScript templates (CSRF payloads) designed to execute within a browser environment to demonstrate how state-changing actions can be forged against authenticated sessions.
Audit Metadata