hunt-open-redirect
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the third-party 'openredirex' tool via 'pip3 install', introducing a dependency from a public software registry.
- [COMMAND_EXECUTION]: The documented methodology includes several Bash script blocks that utilize curl, grep, and other command-line utilities to interact with remote targets and automate vulnerability discovery.
- [PROMPT_INJECTION]: The skill exhibits an indirect injection surface by processing untrusted data from target list files in automated scripts. Evidence: 1. Ingestion points: target list files in SKILL.md methodology; 2. Boundary markers: absent; 3. Capability inventory: curl and Bash execution in SKILL.md; 4. Sanitization: absent.
Audit Metadata