web-app-security
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides specific command-line strings for several penetration testing tools, including
sqlmapfor database auditing,wpscanfor WordPress vulnerability scanning,hydrafor authentication brute-forcing, andkiterunner(kr) for API endpoint discovery. - [DATA_EXFILTRATION]: Includes payloads designed to exfiltrate sensitive information, such as XSS scripts for stealing session cookies (
document.cookie) via external callbacks andsqlmapcommands for dumping entire database tables (--dump). - [REMOTE_CODE_EXECUTION]: Documents techniques for achieving remote code execution on target systems, specifically detailing the use of PHP wrappers (
php://filter,data://) and log poisoning methods to execute system commands. - [PROMPT_INJECTION]: Contains a high density of malicious instruction patterns and attack payloads (SQLi, XSS, HTML injection). These are presented as data for testing but could potentially be interpreted as instructions by an AI agent if not properly delimited.
- [EXTERNAL_DOWNLOADS]: Mentions the use of external wordlists (e.g.,
rockyou.txt) and security tools, although it does not provide direct links to untrusted remote hosting services.
Audit Metadata