cors-cross-origin-misconfiguration
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill provides example JavaScript payloads demonstrating data exfiltration to a placeholder domain (attacker.com). These code snippets are explicitly labeled as Proof-of-Concept (PoC) exploitation examples for security testing and do not represent a threat to the agent or its environment.
- [COMMAND_EXECUTION]: Contains instructions for performing security reconnaissance, such as cache verification using command-line tools like curl. These instructions are standard for the skill's stated purpose of vulnerability analysis and testing.
- [INDIRECT_PROMPT_INJECTION]: The skill documents various web security attack vectors. It informs the agent on how to identify these surfaces during an audit, functioning as a legitimate reference for security professionals.
- [SAFE]: The skill is authored by a security-focused entity and provides structured, professional guidance for identifying and remediating web security vulnerabilities without the use of obfuscation or hidden malicious commands.
Audit Metadata