cors-cross-origin-misconfiguration

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: Provides proof-of-concept JavaScript and HTML snippets that demonstrate the exfiltration of sensitive data to an external domain (attacker.com) via fetch and navigator.sendBeacon.
  • [COMMAND_EXECUTION]: Provides curl commands for manual testing of remote origin reflection and cache poisoning detection.
  • [EXTERNAL_DOWNLOADS]: References external reconnaissance tools and services for subdomain discovery, such as amass, subfinder, and crt.sh.
  • [PROMPT_INJECTION]: The skill facilitates processing untrusted data from external APIs for security analysis. • Ingestion points: Responses from target APIs. • Boundary markers: None specified. • Capability inventory: fetch and navigator.sendBeacon usage in proof-of-concept payloads. • Sanitization: Not addressed as the skill focuses on exploitation demonstration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — cors-cross-origin-misconfiguration