clickjacking-hunter
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides several bash one-liners and a specialized Python utility for security analysis.\n
- Evidence: Use of curl and grep for header inspection in SKILL.md.\n
- Evidence: The clickjacking_agent.py script executes automated endpoint checks.\n- [EXTERNAL_DOWNLOADS]: The skill performs network activity to retrieve and analyze data from external web servers.\n
- Evidence: The requests.get method is used in scripts/clickjacking_agent.py to fetch headers and body content.\n
- Evidence: Phase 1.2 of SKILL.md provides a loop to scan multiple sensitive endpoints.\n- [SAFE]: No malicious patterns or security risks were detected. The skill's operations are consistent with legitimate security auditing practices.\n
- Evidence: The skill focuses on standard web security protections like X-Frame-Options and Content-Security-Policy.\n
- Evidence: The PoC generation is local and intended for manual verification by a security professional.
Audit Metadata