skills/aeondave/malskill/mqtt-pwn/Gen Agent Trust Hub

mqtt-pwn

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the mqtt-pwn framework from Akamai Threat Research's official GitHub repository (github.com/akamai-threat-research/mqtt-pwn).
  • [COMMAND_EXECUTION]: The skill documents the use of shell commands for environment setup, including docker-compose and pip install, as well as interactive shell commands like exec <cmd> for remote command execution on targets during command-and-control (C2) workflows.
  • [DATA_EXFILTRATION]: The tool is designed to identify and extract sensitive information from IoT devices and MQTT brokers, including device fingerprints, Wi-Fi credentials, and broker authentication secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted MQTT brokers which could contain malicious payloads targeting the analysis environment.
  • Ingestion points: Processes messages and topic names gathered during the discovery and messages phases (SKILL.md).
  • Boundary markers: No specific boundary markers or sanitization logic for ingested message content are described in the instructions.
  • Capability inventory: The tool includes high-privilege capabilities such as shell command execution (exec) and persistent storage of captured data in a PostgreSQL database (SKILL.md).
  • Sanitization: The documentation does not specify sanitization or validation routines for data received from the broker before it is processed or stored.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — mqtt-pwn