hunt-graphql

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains examples of shell commands using curl for interacting with GraphQL endpoints, grep for scanning JavaScript bundles, and python3 for running reconnaissance tools. These commands are intended for security research and use placeholders for sensitive inputs.
  • [EXTERNAL_DOWNLOADS]: Mentions several established third-party security tools such as InQL, graphql-voyager, LinkFinder, and clairvoyance. These references are provided as part of the recommended security auditing toolkit.
  • [SAFE]: The skill follows secure documentation practices by avoiding hardcoded credentials, using generic placeholders for target infrastructure, and providing self-verification scripts that are limited to reading the skill's own file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:48 PM
Security Audit — agent-trust-hub — hunt-graphql