dnsexfiltrator

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The skill is explicitly designed for data exfiltration using DNS protocols to bypass standard HTTP/S network filters. It provides instructions to send files from a victim machine to an attacker-controlled domain (e.g., 'exfil.attacker.com').
  • [DATA_EXFILTRATION]: Example commands target sensitive file paths such as 'C:\sensitive\file.zip' and 'C:\Users\victim\Documents' for compression and external transfer.
  • [COMMAND_EXECUTION]: Instructs the use of 'sudo' to execute server-side Python scripts, which constitutes a privilege escalation risk to bind to restricted system ports (53/UDP).
  • [COMMAND_EXECUTION]: Provides specific PowerShell command patterns ('Invoke-DNSExfiltrator') for executing client-side exfiltration code on a target Windows system.
  • [EXTERNAL_DOWNLOADS]: References and encourages the use of external code from a third-party GitHub repository ('github.com/Arno0x/DNSExfiltrator') that is not associated with a trusted organization.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:20 PM
Security Audit — agent-trust-hub — dnsexfiltrator