skills/aeondave/malskill/merlin/Gen Agent Trust Hub

merlin

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions direct the user to download and run server and agent binaries from an external GitHub repository (github.com/Ne0nd0g/merlin) that is not identified as a trusted source.
  • [COMMAND_EXECUTION]: The skill documentation includes commands such as shell which allow for the execution of arbitrary operating system commands on remote agent sessions.
  • [REMOTE_CODE_EXECUTION]: The tool described, Merlin, is a C2 framework explicitly designed for remote management and interaction with multi-OS agents, enabling persistent remote control of target systems.
  • [DATA_EXFILTRATION]: The skill provides explicit functionality for transferring files to and from remote agents via the upload and download commands, representing a significant risk of data exfiltration.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — merlin