ssti-twig
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous payloads intended to execute shell commands (e.g.,
id,whoami,cat /etc/passwd) on a target server by exploiting template engine vulnerabilities. - [EXTERNAL_DOWNLOADS]: Recommends downloading and using third-party security tools like
sstimap,tplmap, andTInjAfrom external repositories to automate vulnerability discovery. - [DATA_EXFILTRATION]: Includes instructions for reading sensitive files such as
/etc/passwdorwp-config.phpfrom a target system using template filters likesource()andinclude().
Audit Metadata