web2-vuln-classes
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill contains examples of malicious prompts (e.g., 'Ignore previous instructions', 'Print your system prompt') used to demonstrate vulnerabilities in LLM-based applications. These are informational data samples and not active instructions to the AI agent.
- [DATA_EXFILTRATION]: Provides references to sensitive file paths such as
~/.aws/credentials,/etc/passwd, and.envas common targets in security research. These references are part of the documentation and do not involve unauthorized data access or exfiltration by the skill. - [OBFUSCATION]: Documents various obfuscation techniques used by attackers, including homoglyph characters in URLs and Unicode tags to hide instructions. These are provided as examples for training and identification purposes.
- [REMOTE_CODE_EXECUTION]: Includes descriptions and payloads for RCE vulnerabilities, such as shell pipelines using
base64andcurl. These are educational snippets intended for security auditing. - [COMMAND_EXECUTION]: Lists various security tool commands (e.g.,
sqlmap,nuclei,ffuf) for manual execution by a security researcher.
Audit Metadata