hunt-graphql
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous command-line examples using curl and grep for interacting with GraphQL endpoints and analyzing JavaScript bundles. These are standard diagnostic tools used for the skill's intended purpose of security research.
- [EXTERNAL_DOWNLOADS]: The documentation references external security tools such as InQL, Clairvoyance, and GraphQL Cop. These references are informative and point to established security auditing tools within the bug bounty community.
- [DATA_EXFILTRATION]: No patterns indicative of sensitive data harvesting or unauthorized network transmission were found. The skill uses standard placeholder values like YOUR_TOKEN for authentication headers.
- [PROMPT_INJECTION]: The skill contains no attempts to bypass safety filters, override system instructions, or extract system prompts.
Audit Metadata