hunt-http-smuggling
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches security research tools from GitHub repositories. The sources include recognized security entities like Assetnote. These downloads are standard for the skill's primary purpose of security research.
- [COMMAND_EXECUTION]: Utilizes system tools such as curl, nc, and python to execute network-based vulnerability probes and run local diagnostic scripts. This also includes the dynamic generation of verification scripts.
- [DATA_EXFILTRATION]: Instructions include generating temporary local files in the /tmp directory to facilitate local vulnerability testing.
- [PROMPT_INJECTION]: The skill is designed to interact with and parse responses from external web servers. This creates a surface for indirect instructions, although this is inherent to its function as a security testing tool.
Audit Metadata