exploit-file-download

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the user to install tools using a high-risk pattern: 'curl -L https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh | bash'. This allows for arbitrary code execution from a personal GitHub repository directly in the shell.
  • [EXTERNAL_DOWNLOADS]: The skill downloads and installs third-party security tools from various GitHub repositories, including maurosoria/dirsearch and ffuf/ffuf, which are not listed as trusted sources.
  • [COMMAND_EXECUTION]: Extensive use of shell commands such as curl, wget, and go install is documented to perform vulnerability scanning and tool installation.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it processes untrusted data from remote target servers. * Ingestion points: Target server responses are read via curl and the requests library in scripts/file_download_tester.py. * Boundary markers: There are no markers or instructions to ignore potential commands in the ingested content. * Capability inventory: The skill can execute commands, write to the filesystem, and store results. * Sanitization: No sanitization is performed on the data retrieved from external targets.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh - DO NOT USE without thorough review
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 16, 2026, 03:47 PM
Security Audit — agent-trust-hub — exploit-file-download