offensive-api-security

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a methodology and educational guide for authorized API penetration testing. All provided scripts and commands are legitimate diagnostic tools (curl, grpcurl, websocat) used for security enumeration, fuzzing, and vulnerability verification.
  • [SAFE]: The network operations demonstrated (curl loops for IDOR, rate limiting, and SSRF testing) target a placeholder domain 'target.example.com' and are presented as examples for security assessments rather than malicious exfiltration.
  • [SAFE]: Remote code and dependency references (mitmproxy, grpcurl, websocat) point to official project documentation and reputable GitHub repositories for well-known security tools.
  • [SAFE]: The inclusion of a 'Detection / Defender View' section provides defensive context, helping users understand the forensic footprint of the described activities, which aligns with best practices for red-team/blue-team training.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 02:26 PM
Security Audit — agent-trust-hub — offensive-api-security