ssti-jinja2

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides an extensive collection of payloads designed to achieve Remote Code Execution (RCE) on target servers using Python's os.popen, os.system, and subprocess.Popen. These are intended for authorized testing of target environments.
  • [DATA_EXFILTRATION]: Includes instructions and payloads for exfiltrating sensitive data from targets, such as reading /etc/passwd, dumping application configuration secrets (e.g., SECRET_KEY), and using out-of-band (OOB) techniques via DNS or HTTP requests.
  • [EXTERNAL_DOWNLOADS]: References several external security tools used for SSTI automation, such as sstimap, tplmap, tinja, and fenjing.
  • [PROMPT_INJECTION]: Contains an indirect prompt injection surface as it instructs the agent to ingest and analyze responses from untrusted external servers to identify frameworks and vulnerabilities.
  • Ingestion points: Analyzing target application output (Step 1, Step 2).
  • Boundary markers: None mentioned for isolating target data.
  • Capability inventory: Includes capabilities for file system writes to the engagement/ directory and command-line tool execution.
  • Sanitization: No explicit sanitization of target server responses is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 09:15 AM
Security Audit — agent-trust-hub — ssti-jinja2