api-fuzzing-bug-bounty
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides command-line examples for using security tools like Kiterunner and curl to interact with target APIs.
- [EXTERNAL_DOWNLOADS]: It references numerous established third-party security repositories and tools on GitHub for reconnaissance and exploitation.
- [DATA_EXFILTRATION]: The skill includes payload examples that utilize external services (e.g., iplogger.com) for testing connectivity and vulnerability verification.
- [PROMPT_INJECTION]: The skill processes external API documentation (e.g., Step 1, reconnaissance). It lacks explicit boundary markers to prevent the agent from following instructions potentially embedded in those files. The skill has capabilities for command execution and network requests, and no sanitization of the external documentation content is described.
Audit Metadata