geoserver-rest-api
Fail
Audited by Gen Agent Trust Hub on Mar 27, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [CREDENTIALS_UNSAFE]: The documentation explicitly lists and uses default administrative credentials ('admin' and 'geoserver') in multiple examples, including the Base64 encoded representation for the Authorization header.
- [COMMAND_EXECUTION]: The skill provides numerous shell command examples using 'curl' to perform sensitive administrative operations such as reloading configurations, resetting caches, and modifying security settings.
- [EXTERNAL_DOWNLOADS]: It describes functionality to load data from arbitrary remote URLs into the GeoServer instance through the 'url.{ext}' endpoint.
- [DATA_EXFILTRATION]: The skill documents the capability to reference local file system paths on the server for data store creation, which presents a significant risk for unauthorized local file access or exposure.
Recommendations
- AI detected serious security threats
Audit Metadata