gophish
Fail
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is explicitly designed for credential harvesting and phishing operations. It details how to clone login pages to capture sensitive user credentials and includes mechanisms for tracking recipient engagement via unique identifiers and tracking pixels.
- [COMMAND_EXECUTION]: The instructions include executing the GoPhish binary directly and using command-line tools like curl to interact with the framework's administrative API to manage campaign data and results.
- [EXTERNAL_DOWNLOADS]: The documentation guides the user to download prebuilt binaries from GitHub releases for deployment.
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection. It ingests untrusted data from external CSV files (containing target names and emails) and uses this data to populate email templates. This interpolation of external content into the agent's output workflow could allow for the injection of malicious instructions or deceptive content into outgoing communications.
Recommendations
- AI detected serious security threats
Audit Metadata