exploit-file-download
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to install tools using a high-risk pattern: 'curl -L https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh | bash'. This allows for arbitrary code execution from a personal GitHub repository directly in the shell.
- [EXTERNAL_DOWNLOADS]: The skill downloads and installs third-party security tools from various GitHub repositories, including maurosoria/dirsearch and ffuf/ffuf, which are not listed as trusted sources.
- [COMMAND_EXECUTION]: Extensive use of shell commands such as curl, wget, and go install is documented to perform vulnerability scanning and tool installation.
- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it processes untrusted data from remote target servers. * Ingestion points: Target server responses are read via curl and the requests library in scripts/file_download_tester.py. * Boundary markers: There are no markers or instructions to ignore potential commands in the ingested content. * Capability inventory: The skill can execute commands, write to the filesystem, and store results. * Sanitization: No sanitization is performed on the data retrieved from external targets.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh - DO NOT USE without thorough review
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata