api-fuzzing-bug-bounty
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references numerous external security tools and wordlists hosted on GitHub and other platforms (e.g., SecLists, Kiterunner, InQL, Astra). These are provided as a resource toolkit for penetration testing and are well-known within the security community.
- [COMMAND_EXECUTION]: Includes example shell commands and scripts (using
curl,python3, andkr) for performing API reconnaissance and vulnerability testing. These snippets are instructional and meant to be executed against authorized targets. - [DATA_EXFILTRATION]: Provides documentation on how to test for data exposure, including example payloads for XXE and SSRF. These examples demonstrate techniques for identifying unauthorized data access as part of a security assessment.
- [SAFE]: The skill serves as a legitimate educational and procedural guide for security professionals. All external links and code examples are consistent with its stated purpose of offensive security testing.
Audit Metadata