exploiting-broken-function-level-authorization

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate security testing tool focused on OWASP API5:2023. It contains no evidence of malicious behavior, data exfiltration, or obfuscation. All functionalities, including the Python script for automated scanning, are consistent with the stated educational and security auditing purposes.\n- [COMMAND_EXECUTION]: The skill includes a Python script (scripts/agent.py) and code snippets in SKILL.md that utilize the requests library to perform network-based vulnerability testing. These actions are transparent and intended for authorized security assessments.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates network communication with external API targets specified by the user to identify security weaknesses. This behavior is fundamental to the purpose of the skill as an API security tester.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 10:50 PM