hunt-business-logic

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an educational and instructional framework for security testing. It contains numerous search patterns (ripgrep, ast-grep, Semgrep) and code templates (Python, HTTP, Bash) designed to help a security researcher or AI agent identify specific classes of business logic errors.
  • [COMMAND_EXECUTION]: The skill includes shell command templates (e.g., rg, ast-grep) intended for source code analysis. These are presented as tools for the user or agent to use in a controlled security audit context and do not involve silent or malicious execution.
  • [REMOTE_CODE_EXECUTION]: The file provides Python script examples using aiohttp and requests for simulating race conditions and testing APIs. These are provided as static templates for the agent to adapt and do not contain any automatic or hidden remote code execution vectors.
  • [DATA_EXFILTRATION]: No exfiltration patterns were detected. The network operations described in the templates target the researcher's own testing endpoint (represented by https://target/) and do not attempt to send sensitive data to unauthorized third-party domains.
  • [PROMPT_INJECTION]: The instructions do not contain attempts to override agent safety guidelines, bypass system constraints, or extract system prompts. The language is purely instructional and aligned with the stated goal of vulnerability hunting.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 07:58 AM
Security Audit — agent-trust-hub — hunt-business-logic