hunt-idor
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides examples of using command-line tools like
curlandffuffor security testing. These are standard tools used for its intended purpose of hunting vulnerabilities in a controlled environment. - [DYNAMIC_EXECUTION]: A Python script snippet is included to generate a wordlist (
ids.txt). This is a common and safe practice for creating test data during security audits and follows a simple, transparent template. - [REMOTE_CODE_EXECUTION]: While the skill uses commands like
curlto fetch JavaScript bundles or API responses, these are performed for analysis purposes rather than for direct shell execution or piping to an interpreter.
Audit Metadata