skills/aeondave/malskill/mcpwn/Gen Agent Trust Hub

mcpwn

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides multiple tools including execute_command, run_in_shell, and start_interactive_shell that allow the agent to execute arbitrary shell commands within the container environment.
  • [PRIVILEGE_ESCALATION]: The runtime environment is configured with sudo NOPASSWD:ALL, granting the agent full administrative control over the underlying Linux container without any authentication barriers.
  • [DATA_EXFILTRATION]: The skill implements a 'CAS artifact plane' on port :5001 and a request_download mechanism specifically designed to move files (including sensitive findings like credentials and private keys) out of the secure workspace to an external URL.
  • [REMOTE_CODE_EXECUTION]: The skill is primarily designed to facilitate remote code execution on target systems through automated payload delivery (upload_to_target) and reverse shell management (tunnel_revshell).
  • [PERSISTENCE]: The documentation provides explicit instructions for establishing persistence on target systems using systemd-run to ensure that unauthorized processes survive shell closures or system restarts.
  • [CREDENTIALS_UNSAFE]: The skill documentation explicitly mentions that the chat transcript and operational results 'intentionally preserve operational findings such as recovered credentials [and] private keys', creating a high risk of accidental exposure of sensitive authentication data.
  • [INDIRECT_PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection because it is designed to ingest and process data from potentially hostile external sources.
  • Ingestion points: Untrusted data enters the context via read_workspace_file (logs/results), read_shell_output (live terminal output), and webhook_requests (external HTTP hits).
  • Boundary markers: The skill lacks explicit instructions for the agent to use delimiters or 'ignore' warnings when sifting through data captured from targets.
  • Capability inventory: The skill possesses extensive capabilities including full shell access, network tunneling, and file-writing tools across its entire instruction set.
  • Sanitization: There is no evidence of output sanitization or validation before the agent interprets data recovered from external targets.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — mcpwn