skills/aeondave/malskill/evilginx2/Gen Agent Trust Hub

evilginx2

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill's primary purpose is the unauthorized capture of sensitive user data, including login credentials and session cookies, by proxying legitimate services. It explicitly describes a 'Session Capture Workflow' designed to harvest authenticated tokens to bypass MFA protections.
  • [COMMAND_EXECUTION]: The skill provides a comprehensive set of shell commands and internal framework commands to set up a phishing infrastructure, manage lures (malicious URLs), and extract captured credentials from the server.
  • [PROMPT_INJECTION]: The skill instructs the agent to facilitate activities that bypass security controls (2FA/MFA) and perform phishing, which often conflicts with standard AI safety guidelines regarding malicious cyber activities.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:20 PM
Security Audit — agent-trust-hub — evilginx2