api-fuzzing-bug-bounty

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references numerous external security tools and wordlists hosted on GitHub and other platforms (e.g., SecLists, Kiterunner, InQL, Astra). These are provided as a resource toolkit for penetration testing and are well-known within the security community.
  • [COMMAND_EXECUTION]: Includes example shell commands and scripts (using curl, python3, and kr) for performing API reconnaissance and vulnerability testing. These snippets are instructional and meant to be executed against authorized targets.
  • [DATA_EXFILTRATION]: Provides documentation on how to test for data exposure, including example payloads for XXE and SSRF. These examples demonstrate techniques for identifying unauthorized data access as part of a security assessment.
  • [SAFE]: The skill serves as a legitimate educational and procedural guide for security professionals. All external links and code examples are consistent with its stated purpose of offensive security testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 01:34 AM
Security Audit — agent-trust-hub — api-fuzzing-bug-bounty