ethical-hacking

Warn

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions explicitly direct the agent to "Handle data exfiltration" and "Create credential harvesting" (found in Sections 7 and 10). Since the skill is configured with filesystem and codebase tools, this creates a direct path for the agent to identify and remove sensitive files or secrets from the local environment.
  • [COMMAND_EXECUTION]: The instructions include tasks for "Create privilege escalation", "Design persistence mechanisms", and "Build red team infrastructure" (Sections 5 and 10). These behaviors are characteristic of malware and unauthorized access, suggesting the agent may attempt to execute commands that modify system security settings or ensure its own continued operation across sessions.
  • [PROMPT_INJECTION]: The skill adopts a persona dedicated to "adversary simulation" and "bypassing security controls." This framing can be used to coerce the agent into disregarding safety guidelines by presenting harmful actions as necessary components of an "ethical hacking" exercise. Additionally, the skill processes external data via the codebase tool without specified boundary markers, making it susceptible to instructions embedded within the analyzed code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 8, 2026, 11:02 AM
Security Audit — agent-trust-hub — ethical-hacking