API Fuzzing for Bug Bounty

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references numerous external security tools and wordlists for API fuzzing and discovery.
  • Evidence: Links to GitHub repositories for tools such as kiterunner, fuzzapi, Astra, and SecLists in the 'Tools Reference' section.
  • [COMMAND_EXECUTION]: The skill provides various command-line templates for reconnaissance and testing tasks.
  • Evidence: Bash blocks demonstrating the use of curl for network requests, kr scan for discovery, and python3 json2paths.py for parsing files.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted external data such as API documentation and server responses, creating a potential attack surface.
  • Ingestion points: The skill processes swagger.json, openapi.json, and live HTTP responses from target APIs.
  • Boundary markers: None explicitly defined to separate untrusted data from instructions.
  • Capability inventory: Shell command execution via curl and python3, and network operations.
  • Sanitization: Not specified, though the skill is designed for manual or semi-automated security testing by an expert user.
  • [SAFE]: The skill contains various exploitation payloads for SQL injection, command injection, and SSRF, which are intended as educational templates for authorized security testing.
  • Evidence: Payloads like 56456 AND sleep(15)# and <!ENTITY xxe SYSTEM "file:///etc/passwd"> are clearly identified as testing examples within the core workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — API Fuzzing for Bug Bounty