csrf
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate security testing tool designed for authorized penetration testing engagements. It provides instructional content and code snippets for evaluating web application defenses against CSRF attacks.
- [COMMAND_EXECUTION]: The skill utilizes common command-line and browser-based tools (curl, browser_evaluate, browser_open) to interact with target web applications for vulnerability assessment. These operations are restricted to the context of the defined security engagement.
- [DATA_EXFILTRATION]: Contains educational examples demonstrating how data could be exfiltrated in a real-world CSRF attack (e.g., using WebSockets or hidden forms). This is included for proof-of-concept purposes and does not indicate malicious behavior by the skill itself.
Audit Metadata