testing-for-host-header-injection

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/agent.py script utilizes the requests library to perform network operations against target URLs to verify header injection vulnerabilities.
  • [COMMAND_EXECUTION]: The SKILL.md file contains several curl commands designed to manually test server responses to arbitrary Host and X-Forwarded-Host headers.
  • [SAFE]: All external references target reputable security research sites including OWASP and PortSwigger.
  • [SAFE]: No evidence of data exfiltration, persistence mechanisms, or obfuscation was found; the skill's activities are consistent with its declared purpose of security auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 06:48 PM