broken-authentication

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates for executing network security tools like hydra and Python scripts for analyzing session tokens. These are intended for use in authorized penetration testing scenarios.
  • [DATA_EXPOSURE]: The skill references standard security wordlists (e.g., rockyou.txt) and common default credentials as part of its educational and testing content. It does not access sensitive local system files like SSH keys or cloud credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from external targets (HTTP responses, JWT tokens, and cookies). While processing untrusted external data is a potential injection vector, the skill mandates a four-step confirmation gate to ensure user oversight and authorization before any actions are taken based on that data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:19 AM
Security Audit — agent-trust-hub — broken-authentication