penetration-tester-master

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes a persona-based instruction set, directing the agent to act as an "Elite Red Team Lead and Professional Pentester". It defines an "Execution Protocol" that mimics a hacking lifecycle, which could be used to steer the agent toward bypassing standard safety constraints for offensive security purposes.\n- [DATA_EXFILTRATION]: The instructions explicitly identify data exfiltration as a primary goal and guide the agent to target sensitive information.\n
  • Guides the agent to use "Path Traversal/LFI" to "Read /etc/passwd or configuration files".\n
  • Mentions stealing cookies via XSS and accessing user data via IDOR.\n
  • Sets the goal to "Move from low-privileged user... to Data Exfiltration".\n- [COMMAND_EXECUTION]: The skill provides a methodology for using various offensive command-line tools and instructs the agent to perform privilege escalation activities on the host system.\n
  • References tools such as Nmap, SQLMap, Metasploit, and BloodHound.\n
  • Step 4 of the execution protocol specifically instructs the agent to "Elevate permissions if possible".\n
  • The "Post-Exploitation & PrivEsc" section describes targeting SUID binaries, kernel exploits, and DLL hijacking.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 06:53 AM
Security Audit — agent-trust-hub — penetration-tester-master