skills/aeondave/malskill/lfisuite/Gen Agent Trust Hub

lfisuite

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill clones an unverified GitHub repository (github.com/D35m0nd142/LFISuite) containing exploitation scripts.
  • [COMMAND_EXECUTION]: The instructions execute the downloaded 'lfisuite.py' script immediately via Python 3.
  • [COMMAND_EXECUTION]: The skill uses 'curl' to inject PHP code into HTTP headers, which facilitates Remote Code Execution (RCE) through log poisoning.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — lfisuite