cors-misconfiguration
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous
curlcommands designed to probe target endpoints for CORS header misconfigurations. These include loops for testing various origin patterns and specific headers to trigger preflight responses. - [DATA_EXFILTRATION]: Contains several HTML and JavaScript proof-of-concept snippets designed to demonstrate how an attacker can read sensitive cross-origin data and exfiltrate it to a remote server using
fetch(),XMLHttpRequest, ornavigator.sendBeacon(). These are provided as educational/demonstrative tools for penetration testing. - [EXTERNAL_DOWNLOADS]: The skill's metadata references external security tools including
burpsuite,corsy, andCORScanner. While it does not provide direct commands to download these, it encourages their use as part of the testing workflow.
Audit Metadata