idor-hunter
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains multiple templates for shell commands and automation scripts intended for network interaction.
references/tools.mdincludescurlcommand templates for manual testing, unauthenticated access checks, and HTTP method switching.references/tools.mdincludesffufcommand templates for numeric ID enumeration and endpoint fuzzing.- [INDIRECT_PROMPT_INJECTION]: The methodology involves the ingestion and analysis of untrusted data from external API responses, creating a surface for indirect prompt injection.
- Ingestion points: Responses from target APIs and web applications during the systematic testing phases (Phase 3 and 5 in
SKILL.md). - Boundary markers: Absent. The skill does not provide instructions to wrap target data in delimiters or include warnings to ignore embedded instructions.
- Capability inventory: The skill provides the agent with instructions to use
curl,ffuf, and custom Python scripts to interact with the target environment. - Sanitization: Absent. There is no mention of filtering or sanitizing response content before the agent evaluates it for vulnerability evidence.
Audit Metadata