tomcat-manager-deploy

Warn

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute powerful local utilities including msfvenom, jar, and curl to generate malicious payloads and interact with remote server APIs.
  • [REMOTE_CODE_EXECUTION]: Provides detailed procedures for generating and deploying malicious Java Archive (WAR) files containing JSP-based reverse shells and web shells to gain unauthorized command execution on the target server.
  • [DATA_EXFILTRATION]: Outlines steps for the discovery and extraction of sensitive target information, such as Tomcat manager credentials, environment variables, and database connection strings stored in application configuration files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 6, 2026, 09:16 AM
Security Audit — agent-trust-hub — tomcat-manager-deploy