crlf-injection

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a technical guide for security researchers documenting CRLF (Carriage Return Line Feed) injection vulnerabilities. It provides payloads and bypass techniques for educational or penetration testing contexts.
  • [OBFUSCATION]: The skill discusses the use of URL encoding (e.g., %0D%0A) and specific Unicode characters (e.g., U+760D, U+760A) as bypasses for security filters. These are documented techniques used in the vulnerability class being explained and are not used to hide malicious logic within the skill itself.
  • [COMMAND_EXECUTION]: No executable code, shell scripts, or unauthorized command execution patterns were found. The skill consists entirely of markdown instructions and examples.
  • [DATA_EXFILTRATION]: There are no network requests, file system access, or credential harvesting patterns identified in the content.
  • [REMOTE_CODE_EXECUTION]: The skill does not reference or download external scripts or packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:13 PM
Security Audit — agent-trust-hub — crlf-injection