skills/aeondave/malskill/set/Gen Agent Trust Hub

set

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions frequently use sudo to execute commands (e.g., sudo setoolkit, sudo python setoolkit), which grants the agent elevated root privileges on the underlying host system.
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading the toolkit from an unverified third-party GitHub repository (trustedsec/social-engineer-toolkit) that is not part of the established verified service providers.
  • [REMOTE_CODE_EXECUTION]: The installation instructions include pip install -r requirements.txt, which installs unversioned and unverified dependencies from external sources, potentially leading to arbitrary code execution during the installation phase.
  • [DATA_EXFILTRATION]: The skill directs the agent to access and read sensitive file paths, including the /root/ directory and credential report logs (e.g., /root/.set/reports/), which is a pattern associated with the exposure of sensitive system and user information.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — set