revshellgen
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to download source code from an external repository (
https://github.com/t0thkr1s/revshellgen) and install a package from a public registry (pip install revshellgen). - [REMOTE_CODE_EXECUTION]: The skill provides a workflow to clone a remote repository and execute its contents (
python3 revshellgen.py). This allows for the execution of arbitrary code from an external, unverifiable source. - [COMMAND_EXECUTION]: The skill is designed to generate shell commands (e.g., Bash, Python, PowerShell, Socat) that establish reverse connections to a remote listener. These commands are typical of post-exploitation activities used to gain control over a target system.
- [PRIVILEGE_ESCALATION]: The skill provides documentation and specific commands for PTY shell upgrades (e.g.,
python3 -c 'import pty; pty.spawn("/bin/bash")') and TTY stabilization, which are techniques used to increase control and capabilities within a compromised shell environment.
Recommendations
- AI detected serious security threats
Audit Metadata