hunt-host-header
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational and testing procedures for Host Header Injection vulnerabilities. All instructions are contextually relevant to the stated purpose of red-teaming and security research.
- [COMMAND_EXECUTION]: The skill utilizes standard command-line tools such as
curl,openssl, andprintfto perform HTTP request manipulation. These commands are templates intended for execution against user-provided targets and do not involve unauthorized local system access. - [DATA_EXFILTRATION]: No patterns for exfiltrating sensitive local files or credentials were found. The skill correctly uses placeholders like
[REDACTED_IP]andyour-test-account@target.comfor documentation purposes. - [PROMPT_INJECTION]: There are no detected instructions that attempt to bypass AI safety filters or override agent behavior. The instructions focus on methodology, citing sources, and technical accuracy.
- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface by processing data from external HTTP responses and email bodies, which could theoretically contain malicious instructions. Ingestion points include the output of
curlandgrepcommands inSKILL.md. While boundary markers and explicit sanitization are absent, the skill's primary focus on validation and specific technical outcomes mitigates the risk.
Audit Metadata