offensive-api-security
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a methodology and educational guide for authorized API penetration testing. All provided scripts and commands are legitimate diagnostic tools (curl, grpcurl, websocat) used for security enumeration, fuzzing, and vulnerability verification.
- [SAFE]: The network operations demonstrated (curl loops for IDOR, rate limiting, and SSRF testing) target a placeholder domain 'target.example.com' and are presented as examples for security assessments rather than malicious exfiltration.
- [SAFE]: Remote code and dependency references (mitmproxy, grpcurl, websocat) point to official project documentation and reputable GitHub repositories for well-known security tools.
- [SAFE]: The inclusion of a 'Detection / Defender View' section provides defensive context, helping users understand the forensic footprint of the described activities, which aligns with best practices for red-team/blue-team training.
Audit Metadata