offensive-api-abuse
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill generates functional Python scripts that utilize libraries such as
requestsandaiohttpto automate authentication brute-forcing and exploit race conditions during transactions. - [DATA_EXFILTRATION]: The skill provides instructions for redirecting server-initiated webhooks and data callbacks to an external attacker-controlled domain (
attacker-listener.example.com) to intercept sensitive events. - [INDIRECT_PROMPT_INJECTION]: The skill defines workflows that ingest data from untrusted external sources, creating a potential surface for indirect prompt injection.
- Ingestion points: The agent is instructed to process API response bodies via
jq, analyze GitHub search results using theghtool, and scan remote JavaScript bundles. - Boundary markers: No explicit delimiters or boundary markers are used when interpolating these external outputs into the workflow.
- Capability inventory: The skill has the capability to perform network requests (
curl,requests,aiohttp) and execute shell commands (gh,grep,parallel). - Sanitization: No sanitization or validation of the content fetched from the API endpoints or GitHub repositories is performed before processing.
- [EXTERNAL_DOWNLOADS]: The engagement methodology depends on several third-party security tools, including Arjun, ParamSpider, jwt_tool, and GraphQL Voyager, which are referenced as essential for discovery and exploitation phases.
Audit Metadata