API Fuzzing for Bug Bounty
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it is designed to ingest and process untrusted external data such as Swagger/OpenAPI specifications and API responses without implementing boundary markers or sanitization.
- Ingestion points: The skill processes external Swagger files like swagger.json and openapi.json, and live API responses.
- Boundary markers: It lacks explicit delimiters or instructions to ignore embedded commands in target data.
- Capability inventory: The skill utilizes network tools such as curl and scripting languages like python3 to interact with and process results from external targets.
- Sanitization: No mechanisms for filtering or escaping content from external API documentation or responses are provided.
Audit Metadata