idor-testing
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a structured guide for security testing and authorized auditing. It does not contain any executable code that performs malicious actions autonomously.
- [SAFE]: A mandatory confirmation gate is implemented, requiring the user to specify the target, confirm authorization, and approve specific commands before any probing occurs.
- [SAFE]: The methodology focuses on testing remote web applications and does not involve accessing sensitive local system files, environment variables, or user credentials.
- [SAFE]: All examples provided for vulnerability detection (URL manipulation, parameter pollution, etc.) and remediation (Django code snippets) are educational and follow standard security industry practices.
- [SAFE]: No obfuscation techniques, hidden commands, or remote code execution patterns were found. Network activity is limited to the user-specified target in an auditing context.
Audit Metadata