hunt-oauth

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a professional security research and educational resource for vulnerability hunting.
  • [SAFE]: Static analysis detected several URLs containing homoglyph characters (e.g., using the Cyrillic 'а' U+0430 or 'о' U+043E). These are intentionally included and clearly labeled in the 'A.5 IDN homograph' section as educational examples of Punycode-based bypasses for security researchers to test against redirect URI validators.
  • [SAFE]: The skill provides numerous search patterns for tools like ripgrep and Semgrep, as well as descriptions of real-world CVEs (2024-2026). This content is consistent with the skill's stated purpose and poses no risk to the agent or the host environment.
  • [SAFE]: There are no signs of credential harvesting, unauthorized network activity, or attempts to bypass agent security constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 07:58 AM
Security Audit — agent-trust-hub — hunt-oauth