password-reset-flaws
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains
curlcommand templates designed for security researchers to test web endpoints for password reset vulnerabilities (e.g., cross-user modification, token predictability). These are standard penetration testing tools and use placeholders likeTARGETandVICTIM. - [SAFE]: The content is purely educational and instructional, referencing the OWASP Web Security Testing Guide (WSTG-ATHN-07, WSTG-ATHN-09). It does not contain obfuscation, hidden commands, or malicious exfiltration attempts targeting the local environment.
Audit Metadata