web-client-side-signing-bypass
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions are purely educational, focusing on manual security analysis techniques for web applications. No automated executable code or suspicious scripting was detected within the skill content.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a methodology for analyzing external, potentially untrusted client-side JavaScript code and network traffic, which defines a theoretical attack surface.
- Ingestion points: Web application JavaScript source code and network response headers/bodies analyzed during Steps 1 and 2.
- Boundary markers: Not applicable, as the skill describes a manual analytical workflow for security research.
- Capability inventory: Use of browser DevTools for debugging, Burp Suite/mitmproxy for traffic interception, and Python requests for network replay.
- Sanitization: Not applicable for a manual reversing methodology.
Audit Metadata