hunt-host-header

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides educational and testing procedures for Host Header Injection vulnerabilities. All instructions are contextually relevant to the stated purpose of red-teaming and security research.
  • [COMMAND_EXECUTION]: The skill utilizes standard command-line tools such as curl, openssl, and printf to perform HTTP request manipulation. These commands are templates intended for execution against user-provided targets and do not involve unauthorized local system access.
  • [DATA_EXFILTRATION]: No patterns for exfiltrating sensitive local files or credentials were found. The skill correctly uses placeholders like [REDACTED_IP] and your-test-account@target.com for documentation purposes.
  • [PROMPT_INJECTION]: There are no detected instructions that attempt to bypass AI safety filters or override agent behavior. The instructions focus on methodology, citing sources, and technical accuracy.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface by processing data from external HTTP responses and email bodies, which could theoretically contain malicious instructions. Ingestion points include the output of curl and grep commands in SKILL.md. While boundary markers and explicit sanitization are absent, the skill's primary focus on validation and specific technical outcomes mitigates the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — hunt-host-header