exploit-lfi

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides Python scripts (lfi_detector.py, lfi_exploiter.py, lfi_bypass_tester.py) and command-line instructions (curl, ffuf) that enable an agent to perform active network probing and exploitation against arbitrary targets.
  • [DATA_EXFILTRATION]: The skill includes extensive lists of sensitive Linux and Windows file paths (e.g., /etc/shadow, C:\Windows\System32\config\SAM, SSH private keys, and .env files) and provides automated scripts designed to extract and save the contents of these files from remote systems.
  • [REMOTE_CODE_EXECUTION]: The instructions and scripts explicitly facilitate achieving RCE on target systems through advanced techniques such as log poisoning (injecting PHP code into User-Agent headers), /proc/self/environ exploitation, and temporary file competition.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests unvalidated text content from remote URLs during its scanning and exploitation phases. This creates a vulnerability surface where a malicious target could serve content designed to influence or hijack the agent's behavior when the response is processed.
  • [DYNAMIC_EXECUTION]: The lfi_storage.py utility uses sys.path.insert to dynamically modify the module search path at runtime to load dependencies from relative directories, which is a pattern that can be exploited if the local file system is partially compromised.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 03:47 PM
Security Audit — agent-trust-hub — exploit-lfi