idor-broken-object-authorization
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to interact with and process data from external API sources (URL parameters, JSON bodies, headers) to identify vulnerabilities. This processing of untrusted external data creates a potential surface for indirect prompt injection.
- Ingestion points: External API responses across all HTTP layers including URL paths, queries, request/response bodies, headers, and cookies.
- Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from interpreting data within those responses as new instructions.
- Capability inventory: The agent is expected to utilize HTTP tools to perform network operations (GET, POST, PUT, DELETE, PATCH, etc.) and analyze the results.
- Sanitization: There are no explicit instructions for the agent to sanitize or validate the external content before processing it for further actions.
Audit Metadata