cors-misconfiguration

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous curl commands designed to probe target endpoints for CORS header misconfigurations. These include loops for testing various origin patterns and specific headers to trigger preflight responses.
  • [DATA_EXFILTRATION]: Contains several HTML and JavaScript proof-of-concept snippets designed to demonstrate how an attacker can read sensitive cross-origin data and exfiltrate it to a remote server using fetch(), XMLHttpRequest, or navigator.sendBeacon(). These are provided as educational/demonstrative tools for penetration testing.
  • [EXTERNAL_DOWNLOADS]: The skill's metadata references external security tools including burpsuite, corsy, and CORScanner. While it does not provide direct commands to download these, it encourages their use as part of the testing workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 09:15 AM
Security Audit — agent-trust-hub — cors-misconfiguration