hunt-cors

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides various bash commands and loops using standard utilities like curl, grep, awk, and httpx to analyze HTTP response headers from target API endpoints.
  • [EXTERNAL_DOWNLOADS]: The instructions include steps to install the corsy tool using pip3 and use nuclei for automated vulnerability scanning.
  • [DATA_EXFILTRATION]: The provided browser-based Proof-of-Concept (PoC) scripts demonstrate how to exfiltrate cross-origin data to a listener (e.g., oastify.com) to verify vulnerability impact. In the context of the skill, this is a legitimate method for security researchers to confirm data theft potential.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:02 PM
Security Audit — agent-trust-hub — hunt-cors