phishing-technique
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPRIVILEGE_ESCALATIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documents the 'ClickFix' technique, which involves tricking victims into executing mshta, powershell, or bash one-liners to download stage-2 payloads from operator infrastructure. This content triggered a Trojan detection (Clip:Mshta-A) in the modern-aitm-tradecraft.md file.
- [COMMAND_EXECUTION]: The instructions require running several network-active tools such as dnstwist, gophish, and evilginx for reconnaissance and campaign execution.
- [PRIVILEGE_ESCALATION]: The skill explicitly commands the use of sudo to run the evilginx binary, granting the process administrative rights over the host system.
- [DATA_EXFILTRATION]: The primary purpose of the AitM techniques described is the exfiltration of credentials and live session tokens to bypass multi-factor authentication.
- [OBFUSCATION]: The skill uses homoglyph domain reconnaissance to create deceptive lookalike domains, which is a form of visual obfuscation.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data including target scope, domains, and user populations in SKILL.md without boundary markers or sanitization, potentially allowing external data to influence the agent's tool execution and campaign logic.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
Audit Metadata