clickjacking-hunter

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides several bash one-liners and a specialized Python utility for security analysis.\n
  • Evidence: Use of curl and grep for header inspection in SKILL.md.\n
  • Evidence: The clickjacking_agent.py script executes automated endpoint checks.\n- [EXTERNAL_DOWNLOADS]: The skill performs network activity to retrieve and analyze data from external web servers.\n
  • Evidence: The requests.get method is used in scripts/clickjacking_agent.py to fetch headers and body content.\n
  • Evidence: Phase 1.2 of SKILL.md provides a loop to scan multiple sensitive endpoints.\n- [SAFE]: No malicious patterns or security risks were detected. The skill's operations are consistent with legitimate security auditing practices.\n
  • Evidence: The skill focuses on standard web security protections like X-Frame-Options and Content-Security-Policy.\n
  • Evidence: The PoC generation is local and intended for manual verification by a security professional.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:09 AM
Security Audit — agent-trust-hub — clickjacking-hunter