okta-attack

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides multiple bash script blocks for automating reconnaissance tasks, including subdomain discovery and DNS CNAME lookups across various Okta regions and regional variants.
  • [EXTERNAL_DOWNLOADS]: The skill performs network probing against external Okta endpoints and DNS servers to identify valid tenants and verify identity provider configurations. It also includes testing logic for OIDC vulnerabilities that targets an external example domain.
  • [DYNAMIC_EXECUTION]: The skill utilizes inline Python commands (python3 -c) to dynamically encode URL payloads within shell loops, which is a standard utility pattern for generating attack strings in security testing workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:32 AM
Security Audit — agent-trust-hub — okta-attack