skills/aeondave/malskill/searchsploit/Gen Agent Trust Hub

searchsploit

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for executing high-privilege and security-relevant CLI tools including 'apt install', 'searchsploit', 'nmap', and 'chmod'.
  • [EXTERNAL_DOWNLOADS]: Documents methods for transferring files between systems using tools such as 'wget', 'certutil', and PowerShell's 'Invoke-WebRequest', which can be used to move malicious payloads.
  • [DYNAMIC_EXECUTION]: Details the compilation of C source code into executable binaries using 'gcc', including instructions for using flags that disable memory protections (e.g., '-fno-stack-protector' and '-z execstack') which are common in exploit development.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines workflows for processing untrusted external data, such as Nmap XML scan results and third-party exploit scripts, creating a potential attack surface for indirect injection.
  • Ingestion points: Nmap scan output files ('scan.xml') and mirrored exploit code ('.c', '.py').
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external file content as untrusted.
  • Capability inventory: Includes shell command execution, C compilation, package installation, and file permission modification.
  • Sanitization: The instructions rely on manual human inspection of exploit headers; no automated sanitization or verification processes are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — searchsploit