pyexfil
Fail
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The skill is explicitly designed to exfiltrate data using over 20 covert channels. It provides Python code snippets that read local files (e.g., 'secrets.txt', 'file.zip') and transmit their contents to remote IP addresses and domains.
- [COMMAND_EXECUTION]: The skill provides ready-to-use shell commands using 'python -c' to execute exfiltration logic directly from the command line.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 'pyexfil' package via 'pip install pyexfil', which introduces specialized software designed to bypass network security controls.
Recommendations
- AI detected serious security threats
Audit Metadata