cors-cross-origin-misconfiguration
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Provides proof-of-concept JavaScript and HTML snippets that demonstrate the exfiltration of sensitive data to an external domain (attacker.com) via fetch and navigator.sendBeacon.
- [COMMAND_EXECUTION]: Provides curl commands for manual testing of remote origin reflection and cache poisoning detection.
- [EXTERNAL_DOWNLOADS]: References external reconnaissance tools and services for subdomain discovery, such as amass, subfinder, and crt.sh.
- [PROMPT_INJECTION]: The skill facilitates processing untrusted data from external APIs for security analysis. • Ingestion points: Responses from target APIs. • Boundary markers: None specified. • Capability inventory: fetch and navigator.sendBeacon usage in proof-of-concept payloads. • Sanitization: Not addressed as the skill focuses on exploitation demonstration.
Audit Metadata