open-redirect
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALNO_CODE
Full Analysis
- [SAFE]: The skill functions as an informational reference and attack playbook for security auditing. It contains descriptions of common vulnerability patterns, bypass techniques, and testing checklists intended for security researchers and AI agents.
- [OBFUSCATION]: The skill documentation describes various obfuscation techniques used in web redirects, including homoglyph domains (e.g., using full-width characters) and multiple URL encoding. These examples are used for educational purposes to illustrate how filters can be bypassed and are not used to conceal the skill's own instructions.
- [DATA_EXFILTRATION]: No commands or logic for unauthorized data access, credential harvesting, or exfiltration to external domains were detected. The example URLs provided in the text (e.g., 'evil.com') are standard placeholders used in security documentation.
- [NO_CODE]: The skill consists entirely of Markdown-formatted instructions and text-based examples. It does not contain any executable scripts, automated tool invocations, or configuration files that could pose a runtime risk.
Recommendations
- CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata