tplmap
Fail
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download software from an unverified external repository:
https://github.com/epinna/tplmap. This introduces risks from third-party code that is not subject to the platform's security controls. - [COMMAND_EXECUTION]: The instructions include multiple shell commands for execution by the agent, including
git clone,pip install, andpython2script execution. These commands are used to prepare and launch an exploitation environment. - [REMOTE_CODE_EXECUTION]: The skill's primary functionality is to automate the discovery and exploitation of RCE vulnerabilities. It provides specific instructions and command-line flags (e.g.,
--os-shell,--os-cmd) to gain unauthorized command execution on remote targets. - [EXTERNAL_DOWNLOADS]: The skill suggests running
pip install -r requirements.txton a file from an untrusted source, which could lead to the installation of malicious Python dependencies in the agent's environment.
Recommendations
- AI detected serious security threats
Audit Metadata