session-fixation
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains multiple bash command examples utilizing
curlto capture, compare, and test session cookies. These commands are standard security testing tools used to interact with a user-specified target environment. - [DYNAMIC_EXECUTION]: A Python one-liner is included to decode Base64-encoded session tokens for inspection. This is a benign data analysis task performed locally on the user's machine.
- [SAFE]: The skill follows established security testing methodologies (OWASP WSTG) and provides remediation guidance. It does not attempt to exfiltrate data, bypass safety controls, or establish persistence.
Audit Metadata