evilginx2
Fail
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill's primary purpose is the unauthorized capture of sensitive user data, including login credentials and session cookies, by proxying legitimate services. It explicitly describes a 'Session Capture Workflow' designed to harvest authenticated tokens to bypass MFA protections.
- [COMMAND_EXECUTION]: The skill provides a comprehensive set of shell commands and internal framework commands to set up a phishing infrastructure, manage lures (malicious URLs), and extract captured credentials from the server.
- [PROMPT_INJECTION]: The skill instructs the agent to facilitate activities that bypass security controls (2FA/MFA) and perform phishing, which often conflicts with standard AI safety guidelines regarding malicious cyber activities.
Recommendations
- AI detected serious security threats
Audit Metadata