skills/uphiago/recon-skills/hunt-idor/Gen Agent Trust Hub

hunt-idor

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous command-line instructions for the agent to execute, including curl for network requests, ffuf for fuzzing, and grep for local file searching. These are intended for identifying security vulnerabilities on a target system.\n- [REMOTE_CODE_EXECUTION]: The skill includes a Python script template that the agent is instructed to generate and execute to create wordlists. This dynamic generation and execution of code is a core functional component but presents an execution surface.\n- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface. Ingestion points: The agent is instructed to browse targets and extract identifiers from API paths, query parameters, JavaScript source code, and API responses (SKILL.md). Boundary markers: Absent; there are no instructions to delimit or ignore instructions found within target data. Capability inventory: The agent has access to shell execution (curl, ffuf, grep) and script generation (Python). Sanitization: Absent; the skill does not specify escaping or filtering for the external content before it is used in further commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:48 PM
Security Audit — agent-trust-hub — hunt-idor