api-fuzzing-bug-bounty
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an educational and procedural guide for authorized API security assessments and does not contain malicious code or instructions.
- [EXTERNAL_DOWNLOADS]: The documentation references established security tools and repositories hosted on GitHub and Netlify, such as SecLists, Kiterunner, and InQL. These references are consistent with the skill's purpose and point to reputable resources in the security community.
- [COMMAND_EXECUTION]: Provides example bash and curl commands for API reconnaissance and exploitation testing. These are presented as instructional templates for the user and do not involve automatic execution of untrusted scripts by the agent.
- [PROMPT_INJECTION]: The skill includes an offensive security disclaimer and does not contain patterns intended to override agent safety guidelines or manipulate instructions.
- [DATA_EXFILTRATION]: Analysis confirmed the absence of hardcoded credentials, unauthorized access to sensitive local files, or patterns for exfiltrating user data.
Audit Metadata