modlishka
Fail
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [DATA_EXFILTRATION]: The skill describes a system for capturing sensitive user information, such as login credentials and session cookies, as its primary purpose. Evidence: "Modlishka: flexible reverse proxy phishing framework that captures credentials and session cookies while bypassing 2FA/MFA.".
- [EXTERNAL_DOWNLOADS]: The skill includes instructions to download source code from an external GitHub repository not associated with the primary author or trusted organizations. Evidence: "git clone https://github.com/drk1wi/Modlishka".
- [COMMAND_EXECUTION]: The skill provides shell commands to build and run a binary that performs man-in-the-middle attacks. Evidence: "./Modlishka -target https://accounts.google.com".
Recommendations
- AI detected serious security threats
Audit Metadata