skills/aeondave/malskill/tplmap/Gen Agent Trust Hub

tplmap

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download software from an unverified external repository: https://github.com/epinna/tplmap. This introduces risks from third-party code that is not subject to the platform's security controls.
  • [COMMAND_EXECUTION]: The instructions include multiple shell commands for execution by the agent, including git clone, pip install, and python2 script execution. These commands are used to prepare and launch an exploitation environment.
  • [REMOTE_CODE_EXECUTION]: The skill's primary functionality is to automate the discovery and exploitation of RCE vulnerabilities. It provides specific instructions and command-line flags (e.g., --os-shell, --os-cmd) to gain unauthorized command execution on remote targets.
  • [EXTERNAL_DOWNLOADS]: The skill suggests running pip install -r requirements.txt on a file from an untrusted source, which could lead to the installation of malicious Python dependencies in the agent's environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — tplmap