dns-rebinding-attacks
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references established security research tools and frameworks, providing links to public GitHub repositories maintained by recognized security firms (e.g., NCC Group) and prominent security researchers.
- [COMMAND_EXECUTION]: The documentation includes standard setup and build instructions (e.g., git clone, go build) for running the Singularity framework, which is a common utility for security professionals testing DNS vulnerabilities.
- [PROMPT_INJECTION]: The skill uses instructional text to establish a specialized persona for the AI agent as a DNS rebinding expert. This is a common way to scope the agent's knowledge and is not an attempt to bypass safety constraints.
- [REMOTE_CODE_EXECUTION]: JavaScript snippets are included as functional examples to demonstrate how rebinding attacks target internal services such as cloud metadata APIs, Kubernetes APIs, and local Docker management ports. These are educational references within a security research context.
Audit Metadata