hunt-graphql
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill contains examples of shell commands using
curlfor interacting with GraphQL endpoints,grepfor scanning JavaScript bundles, andpython3for running reconnaissance tools. These commands are intended for security research and use placeholders for sensitive inputs. - [EXTERNAL_DOWNLOADS]: Mentions several established third-party security tools such as
InQL,graphql-voyager,LinkFinder, andclairvoyance. These references are provided as part of the recommended security auditing toolkit. - [SAFE]: The skill follows secure documentation practices by avoiding hardcoded credentials, using generic placeholders for target infrastructure, and providing self-verification scripts that are limited to reading the skill's own file content.
Audit Metadata