skills/aeondave/malskill/cupp/Gen Agent Trust Hub

cupp

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone an external repository from GitHub (https://github.com/Mebus/cupp). This repository is not associated with any trusted organization or well-known service defined in the security policy.- [REMOTE_CODE_EXECUTION]: Following the download, the skill executes the external script using 'python3 cupp.py'. This download-and-execute pattern from an untrusted source is a significant security risk as the agent executes code without verification of its integrity.- [COMMAND_EXECUTION]: The skill provides command-line instructions for interactive profiling, wordlist generation, and integration with offensive security tools like Hydra and Hashcat.- [PROMPT_INJECTION]: The skill establishes a data ingestion surface for personal identifiable information (PII) such as names, birthdates, and nicknames. Since this untrusted data is processed into interactive prompts for the profiling tool without boundary markers or sanitization, it creates a risk for indirect prompt injection if the ingested data contains malicious instructions targeting the agent context.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — cupp