cpanel-ftp
Fail
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill includes hardcoded example passwords within the bash command examples provided for the agent.
- Evidence: 'Ftp#MatKhauManh2026!' in
SKILL.md. - Evidence: 'Ftp#MatKhauMoi2026!' in
SKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill contains instructions for reading and modifying the
.htaccessfile, which creates an attack surface for indirect prompt injection from server-side data. - Ingestion points: The agent is instructed to use
cpanel file:read public_html .htaccessto view configuration content. - Boundary markers: Absent; the instructions do not include delimiters or warnings to ignore embedded instructions within the file.
- Capability inventory: The skill allows for FTP account creation/deletion and file system modification via
cpanel file:save. - Sanitization: Absent; the skill suggests reading the file, manual local modification, and saving the result back to the server without validation.
- [COMMAND_EXECUTION]: The skill facilitates administrative operations through the
cpanelCLI tool, which allows the agent to execute specific server management commands.
Recommendations
- AI detected serious security threats
Audit Metadata