mcpwn
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides multiple tools including
execute_command,run_in_shell, andstart_interactive_shellthat allow the agent to execute arbitrary shell commands within the container environment. - [PRIVILEGE_ESCALATION]: The runtime environment is configured with
sudo NOPASSWD:ALL, granting the agent full administrative control over the underlying Linux container without any authentication barriers. - [DATA_EXFILTRATION]: The skill implements a 'CAS artifact plane' on port
:5001and arequest_downloadmechanism specifically designed to move files (including sensitive findings like credentials and private keys) out of the secure workspace to an external URL. - [REMOTE_CODE_EXECUTION]: The skill is primarily designed to facilitate remote code execution on target systems through automated payload delivery (
upload_to_target) and reverse shell management (tunnel_revshell). - [PERSISTENCE]: The documentation provides explicit instructions for establishing persistence on target systems using
systemd-runto ensure that unauthorized processes survive shell closures or system restarts. - [CREDENTIALS_UNSAFE]: The skill documentation explicitly mentions that the chat transcript and operational results 'intentionally preserve operational findings such as recovered credentials [and] private keys', creating a high risk of accidental exposure of sensitive authentication data.
- [INDIRECT_PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection because it is designed to ingest and process data from potentially hostile external sources.
- Ingestion points: Untrusted data enters the context via
read_workspace_file(logs/results),read_shell_output(live terminal output), andwebhook_requests(external HTTP hits). - Boundary markers: The skill lacks explicit instructions for the agent to use delimiters or 'ignore' warnings when sifting through data captured from targets.
- Capability inventory: The skill possesses extensive capabilities including full shell access, network tunneling, and file-writing tools across its entire instruction set.
- Sanitization: There is no evidence of output sanitization or validation before the agent interprets data recovered from external targets.
Recommendations
- AI detected serious security threats
Audit Metadata