hunt-business-logic

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides functional shell command templates using curl and grep for interacting with web endpoints. These are intended for the user agent to perform security probing (e.g., testing rate limits, tampering with payment flows, and discovering internal paths) against target URLs as part of the skill's primary research purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process data from external targets, which creates a surface for potential indirect prompt injection attacks.\n
  • Ingestion points: The agent is guided to fetch and analyze content from robots.txt, sitemap.xml, frontend JavaScript bundles, and HTTP response headers from user-defined targets.\n
  • Boundary markers: No explicit delimiters or instructions to ignore potential commands embedded within the retrieved content are provided.\n
  • Capability inventory: The skill utilizes curl for network operations and grep for string pattern matching across the ingested data.\n
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the content retrieved from external sources before the agent processes it.\n- [SAFE]: The external references provided, such as links to HackerOne reports and GitHub, point to well-known and reputable security research platforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:02 PM
Security Audit — agent-trust-hub — hunt-business-logic