bug-bounty
Fail
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The toolkit downloads and executes installation scripts from remote sources, including official scripts from Ollama and Homebrew. It also references remote exploit scripts, such as a Drupa7 CVE-2018-7600 PoC.
- [PROMPT_INJECTION]: The skill repository contains a vast library of prompt injection and jailbreak payloads intended for VAPT engagements. It includes specialized logic to generate prompts that attempt to extract system instructions or hijack agent goals.
- [EXTERNAL_DOWNLOADS]: The pipeline automatically fetches various wordlists, configuration files, and approximately 50 external security utilities from third-party GitHub repositories and official project domains.
- [DATA_EXFILTRATION]: Payloads are included that attempt to exfiltrate sensitive data via Markdown image beacons and out-of-band (OOB) DNS/HTTP channels using services like interactsh.
- [COMMAND_EXECUTION]: The framework orchestrates the runtime execution of a large suite of external scanners, including nuclei, sqlmap, and dalfox. It employs advanced obfuscation techniques in its payloads, such as homoglyph domain substitution (e.g., 'legіt.com') and invisible Unicode character encoding (U+2062, U+2064) to conceal prompt instructions.
Recommendations
- HIGH: Downloads and executes remote code from: https://ollama.ai/install.sh - DO NOT USE without thorough review
- CRITICAL: 4 file(s) identified as malware by FileRep - DO NOT USE
- Contains 4 malicious URL(s) - DO NOT USE
Audit Metadata