cors-misconfig

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a comprehensive educational guide for testing Cross-Origin Resource Sharing (CORS) misconfigurations. It follows standard security testing patterns and provides methodologies for ethical hacking and vulnerability assessment.
  • [COMMAND_EXECUTION]: The skill includes curl commands intended for manual header injection testing. These commands are benign and used for observing server responses rather than executing arbitrary code on the host machine.
  • [INDIRECT_PROMPT_INJECTION]: The skill mentions external sources like OWASP, which is a well-known and trusted organization in the cybersecurity community. The methodology is consistent with industry standards (WSTG-CLNT-07).
  • [REMOTE_CODE_EXECUTION]: The JavaScript PoC (Proof of Concept) snippets included are intended to demonstrate how a vulnerability could be exploited in a browser context. They do not contain remote code execution vulnerabilities for the AI agent or the user's local system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:34 PM
Security Audit — agent-trust-hub — cors-misconfig