auditing-cors-policy

Fail

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a Python script (audit_cors.py) to perform security testing and utilizes curl for baseline network requests during the audit process.
  • [EXTERNAL_DOWNLOADS]: The skill initiates network connections to external, user-specified target URLs to retrieve and analyze HTTP response headers for security evaluation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted HTTP headers from external servers. While this represents an ingestion surface for untrusted data, the skill uses the information for analysis rather than executing it as instructions. Ingestion points: HTTP response headers from analyzed targets. Boundary markers: Absent. Capability inventory: Shell execution via Python and curl. Sanitization: Absent.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 9, 2026, 03:42 AM
Security Audit — agent-trust-hub — auditing-cors-policy