hunt-api-misconfig
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an educational resource for identifying API security vulnerabilities. It provides methodologies, payload examples, and discovery paths for security professionals.
- [SAFE]: Code snippets provided (JavaScript, Python, and Bash) are illustrative examples used to demonstrate vulnerable patterns or testing commands (e.g., CORS testing via curl, JWT construction) rather than executable malicious scripts targeting the agent's environment.
- [SAFE]: External links and references point to established security research platforms, vulnerability writeups, and official project issue trackers (e.g., GitHub, HackerOne, arXiv, and PortSwigger).
- [SAFE]: No indicators of prompt injection, data exfiltration, obfuscation, or persistence mechanisms were detected. The skill's behavior is consistent with its stated purpose of assisting in API security hunting.
Audit Metadata