open-redirect

Fail

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: CRITICALNO_CODE
Full Analysis
  • [SAFE]: The content is purely educational and instructional, acting as a reference for security researchers or agents performing security audits.
  • [NO_CODE]: The skill is composed entirely of Markdown documentation. It does not include any Python or Node.js scripts, configuration files that execute commands, or binary assets.
  • [PROMPT_INJECTION]: The skill uses an 'AI LOAD INSTRUCTION' to set the context for the agent's knowledge base regarding open redirect techniques. This is a standard instructional pattern and does not attempt to bypass safety filters or override core agent instructions.
  • [DATA_EXFILTRATION]: While the skill mentions sensitive concepts like OAuth tokens and IAM credentials, these are discussed in the context of theoretical attack chains. No actual commands for reading local credentials or sending data to external servers are present.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts (e.g., no curl/bash pipes or dynamic evaluations of external strings).
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — open-redirect