skills/aeondave/malskill/pupy/Gen Agent Trust Hub

pupy

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to pull a Docker image from an external repository (n1nj4sec/pupy) that is not associated with the author or a known trusted vendor.
  • [REMOTE_CODE_EXECUTION]: Downloading and running a Docker image from an unverified source (docker run -it --rm -p 8443:8443 n1nj4sec/pupy pupysh) facilitates the execution of arbitrary third-party code within the agent's environment.
  • [COMMAND_EXECUTION]: Provides specific commands for generating malware implants (gen -f exe) and establishing Command and Control (C2) listeners to manage remote sessions.
  • [DATA_EXFILTRATION]: Explicitly promotes the use of post-exploitation modules for stealing sensitive information, such as credential dumping (post.gather.credentials), keylogging (post.gather.keylogger), and capturing screenshots from the target system.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — pupy