hunt-api-misconfig
Fail
Audited by Snyk on Jul 31, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The file is an explicit offensive playbook: it contains step-by-step techniques for data exfiltration, credential forgery/theft, privilege escalation, WAF/WAF-parsing bypasses, and RCE chains suitable for deliberate abuse.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill describes Swagger UI loading an external OpenAPI spec at runtime via ?configUrl=https://evil/spec.json, which is a remote URL that, when fetched by the victim's browser, directly controls the UI's behavior and can induce authenticated requests — a runtime external dependency controlling behavior (https://evil/spec.json).
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata