smuggler
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a third-party repository from
https://github.com/defparam/smuggler. This external source is not a recognized trusted organization. - [COMMAND_EXECUTION]: The skill executes multiple commands that run third-party code, including
pip3 install -r requirements.txtto install unverified dependencies andpython3 smuggler.pyto run the downloaded script. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of URL lists and piped input to perform network operations.
- Ingestion points: The skill reads from user-provided files such as
urls.txtandendpoints.txt, or via standard input piping from tools likesubfinderandhttpx. - Boundary markers: There are no explicit instructions or delimiters to isolate or ignore potentially malicious instructions embedded in the processed target data.
- Capability inventory: The skill utilizes network socket operations to send HTTP mutations via
smuggler.pyand writes results to local files using the-lflag. - Sanitization: No sanitization or validation of the input URLs is mentioned in the instructions before they are passed to the execution script.
Audit Metadata