geoserver-rest-api

Fail

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The documentation explicitly lists and uses default administrative credentials ('admin' and 'geoserver') in multiple examples, including the Base64 encoded representation for the Authorization header.
  • [COMMAND_EXECUTION]: The skill provides numerous shell command examples using 'curl' to perform sensitive administrative operations such as reloading configurations, resetting caches, and modifying security settings.
  • [EXTERNAL_DOWNLOADS]: It describes functionality to load data from arbitrary remote URLs into the GeoServer instance through the 'url.{ext}' endpoint.
  • [DATA_EXFILTRATION]: The skill documents the capability to reference local file system paths on the server for data store creation, which presents a significant risk for unauthorized local file access or exposure.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 27, 2026, 08:54 AM
Security Audit — agent-trust-hub — geoserver-rest-api