hunt-oauth
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a professional security research and educational resource for vulnerability hunting.
- [SAFE]: Static analysis detected several URLs containing homoglyph characters (e.g., using the Cyrillic 'а' U+0430 or 'о' U+043E). These are intentionally included and clearly labeled in the 'A.5 IDN homograph' section as educational examples of Punycode-based bypasses for security researchers to test against redirect URI validators.
- [SAFE]: The skill provides numerous search patterns for tools like ripgrep and Semgrep, as well as descriptions of real-world CVEs (2024-2026). This content is consistent with the skill's stated purpose and poses no risk to the agent or the host environment.
- [SAFE]: There are no signs of credential harvesting, unauthorized network activity, or attempts to bypass agent security constraints.
Audit Metadata