skills/aeondave/malskill/phpsploit/Gen Agent Trust Hub

phpsploit

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install the phpsploit package, a third-party offensive security framework, using the pip package manager.
  • [COMMAND_EXECUTION]: Provides functionality to execute arbitrary system commands on a remote target system via the run command and explicitly references the use of privilege escalation plugins like sudo-bypass.
  • [REMOTE_CODE_EXECUTION]: Includes a PHP web shell stager that executes code supplied in HTTP headers using eval on base64-encoded data, which is a standard pattern for achieving remote code execution.
  • [PROMPT_INJECTION]: The skill processes output from a remote target system without explicit boundary markers or sanitization, creating an attack surface for indirect prompt injection if the target system is controlled by a malicious actor.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — phpsploit