API Fuzzing for Bug Bounty
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references numerous external security tools and wordlists for API fuzzing and discovery.
- Evidence: Links to GitHub repositories for tools such as
kiterunner,fuzzapi,Astra, andSecListsin the 'Tools Reference' section. - [COMMAND_EXECUTION]: The skill provides various command-line templates for reconnaissance and testing tasks.
- Evidence: Bash blocks demonstrating the use of
curlfor network requests,kr scanfor discovery, andpython3 json2paths.pyfor parsing files. - [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted external data such as API documentation and server responses, creating a potential attack surface.
- Ingestion points: The skill processes
swagger.json,openapi.json, and live HTTP responses from target APIs. - Boundary markers: None explicitly defined to separate untrusted data from instructions.
- Capability inventory: Shell command execution via
curlandpython3, and network operations. - Sanitization: Not specified, though the skill is designed for manual or semi-automated security testing by an expert user.
- [SAFE]: The skill contains various exploitation payloads for SQL injection, command injection, and SSRF, which are intended as educational templates for authorized security testing.
- Evidence: Payloads like
56456 AND sleep(15)#and<!ENTITY xxe SYSTEM "file:///etc/passwd">are clearly identified as testing examples within the core workflow.
Audit Metadata