performing-graphql-depth-limit-attack

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate security testing tool designed for authorized GraphQL API audits. No malicious patterns or deceptive behaviors were identified in the scripts or documentation.\n- [COMMAND_EXECUTION]: The skill includes Python scripts that use the requests library to perform network-based security tests. These operations are essential for the skill's purpose and are directed only at target URLs provided by the user.\n- [DATA_EXFILTRATION]: Network activity is restricted to the GraphQL endpoints specified during testing. No access to sensitive local files or unauthorized credential harvesting was found.\n- [EXTERNAL_DOWNLOADS]: The skill requires the standard requests Python package. This dependency is well-known and appropriate for the skill's functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 08:41 PM