IDOR Vulnerability Testing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill guides the agent to capture and analyze untrusted data from external sources, such as API responses and file metadata, creating a surface for indirect prompt injection. If a target application returns malicious content designed to influence the agent, it could lead to unauthorized behavior.
  • Ingestion points: The Reconnaissance and Detection sections involve processing data from external API endpoints and identifiers.
  • Boundary markers: The skill does not provide delimiters or instructions for the agent to treat external content as untrusted.
  • Capability inventory: The workflow involves performing analysis and suggesting actions based on untrusted external inputs.
  • Sanitization: No mechanisms for validating or sanitizing external application responses are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — IDOR Vulnerability Testing