hunt-open-redirect
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell commands for automating vulnerability scanning, including the use of
curlfor network requests and loops for testing payloads. - [EXTERNAL_DOWNLOADS]: The skill recommends installing
openredirexviapip3, which is an external third-party package. - [PROMPT_INJECTION]: The skill uses authoritative language like 'Crown Jewel Targets' and 'Highest-value chains' to direct the agent toward high-impact exploitation strategies.
- [COMMAND_EXECUTION]: Provides instructions for manipulating OAuth flows and SSRF escalations, which involves crafting specific HTTP requests to interact with internal or external services.
Audit Metadata