API Fuzzing for Bug Bounty

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a wide range of external security tools, Wordlists, and scripts hosted on GitHub from various contributors in the cybersecurity community (e.g., SecLists, Kiterunner, InQL, graphw00f, and Astra). These resources are cited as standard utilities for security assessment and reconnaissance.
  • [COMMAND_EXECUTION]: The skill includes numerous examples of command-line interface (CLI) operations and exploit payloads. These examples cover reconnaissance (e.g., kiterunner scans), manual vulnerability testing (e.g., SQL injection strings in JSON, command injection attempts like ;ls /), and GraphQL introspection queries. These instructions are provided as a reference for authorized security testing and do not contain scripts that execute automatically on the agent's host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 01:14 AM