hunt-captcha-bypass

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely documentation-based and does not include any executable scripts, helper tools, or automated exploitation code.
  • [PROMPT_INJECTION]: The content includes a 'Mandatory confirmation gate' which functions as a safety guardrail. It instructs the agent to verify authorization, scope, and user intent before performing any actions, which reinforces rather than bypasses safety protocols.
  • [REMOTE_CODE_EXECUTION]: The skill mentions external tools and methodologies but does not facilitate their download or execution within the skill's own environment. It explicitly states that helpers and research assets are not bundled.
  • [COMMAND_EXECUTION]: While it describes bash commands for reading files (e.g., cat scope.txt), these are presented as read-only examples for local scope verification during an authorized engagement.
  • [DATA_EXFILTRATION]: There are no patterns suggesting the harvesting or transmission of sensitive data. The skill focuses on testing the integrity of CAPTCHA validation on target endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 01:25 AM
Security Audit — agent-trust-hub — hunt-captcha-bypass