cors-cross-origin-misconfiguration

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides example JavaScript payloads demonstrating data exfiltration to a placeholder domain (attacker.com). These code snippets are explicitly labeled as Proof-of-Concept (PoC) exploitation examples for security testing and do not represent a threat to the agent or its environment.
  • [COMMAND_EXECUTION]: Contains instructions for performing security reconnaissance, such as cache verification using command-line tools like curl. These instructions are standard for the skill's stated purpose of vulnerability analysis and testing.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents various web security attack vectors. It informs the agent on how to identify these surfaces during an audit, functioning as a legitimate reference for security professionals.
  • [SAFE]: The skill is authored by a security-focused entity and provides structured, professional guidance for identifying and remediating web security vulnerabilities without the use of obfuscation or hidden malicious commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:50 AM
Security Audit — agent-trust-hub — cors-cross-origin-misconfiguration