python-code-injection

Fail

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill contains a library of payloads for executing arbitrary Python code via eval(), exec(), and compile(), including sophisticated sandbox escape techniques involving the Python subclass chain.
  • [COMMAND_EXECUTION]: Provides instructions for executing OS commands on target systems through modules like os and subprocess, and includes multiple payloads for establishing interactive reverse shells.
  • [DATA_EXFILTRATION]: Outlines methods for discovering and stealing sensitive information such as /etc/passwd, cloud provider credentials, and environment variables from compromised systems.
  • [DATA_EXFILTRATION]: Includes techniques for exfiltrating data via DNS and HTTP side-channels to bypass network restrictions in blind injection scenarios.
  • [DATA_EXFILTRATION]: Directs the agent to store captured credentials and output in an evidence/ directory for subsequent exfiltration.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 23, 2026, 02:06 AM
Security Audit — agent-trust-hub — python-code-injection