ssti-jinja2
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides an extensive collection of payloads designed to achieve Remote Code Execution (RCE) on target servers using Python's
os.popen,os.system, andsubprocess.Popen. These are intended for authorized testing of target environments. - [DATA_EXFILTRATION]: Includes instructions and payloads for exfiltrating sensitive data from targets, such as reading
/etc/passwd, dumping application configuration secrets (e.g.,SECRET_KEY), and using out-of-band (OOB) techniques via DNS or HTTP requests. - [EXTERNAL_DOWNLOADS]: References several external security tools used for SSTI automation, such as
sstimap,tplmap,tinja, andfenjing. - [PROMPT_INJECTION]: Contains an indirect prompt injection surface as it instructs the agent to ingest and analyze responses from untrusted external servers to identify frameworks and vulnerabilities.
- Ingestion points: Analyzing target application output (Step 1, Step 2).
- Boundary markers: None mentioned for isolating target data.
- Capability inventory: Includes capabilities for file system writes to the
engagement/directory and command-line tool execution. - Sanitization: No explicit sanitization of target server responses is described.
Audit Metadata