hunt-saml

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a reference guide for security testing and bug hunting in SAML/SSO environments. It provides technical descriptions of well-known attack vectors such as XML Signature Wrapping (XSW), Comment Injection, and Signature Stripping.\n- [SAFE]: The commands provided in the attack surface and workflow sections use standard system utilities (grep, cat, echo, base64, xmllint) for local data processing and reconnaissance on the user's targeted environment.\n- [SAFE]: While the skill contains XML snippets representing malicious payloads (e.g., XXE, XSW), these are clearly presented as examples for educational and testing purposes within a security research context.\n- [SAFE]: References to external tools (SAMLRaider) and related skills (hunt-ato, hunt-auth-bypass) are consistent with legitimate security auditing practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:02 PM
Security Audit — agent-trust-hub — hunt-saml