hunt-idor
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous command-line examples for common security tools such as
ripgrep(rg),ffuf,semgrep, andast-grep. These are used to identify vulnerability signals (like sequential IDs or predictable UUIDs) in target source code or API responses. The commands are presented as educational templates and do not execute automatically. - [DATA_EXFILTRATION]: No evidence of malicious data exfiltration was found. The skill describes how to detect data exposure in third-party applications (the targets of the hunting skill) but does not perform unauthorized network operations from the host environment.
- [REMOTE_CODE_EXECUTION]: The skill does not perform or facilitate remote code execution from untrusted sources. It provides a Python code snippet for calculating UUIDv1 timestamps, which is handled locally and is logic-based.
- [SAFE]: The content is highly transparent, referencing well-known security research, official CVE entries, and established industry platforms (HackerOne, Bugcrowd, GitHub Security Lab). The provided commands and scripts are standard practices for security auditing and bug hunting.
Audit Metadata