penetration-tester-master
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes a persona-based instruction set, directing the agent to act as an "Elite Red Team Lead and Professional Pentester". It defines an "Execution Protocol" that mimics a hacking lifecycle, which could be used to steer the agent toward bypassing standard safety constraints for offensive security purposes.\n- [DATA_EXFILTRATION]: The instructions explicitly identify data exfiltration as a primary goal and guide the agent to target sensitive information.\n
- Guides the agent to use "Path Traversal/LFI" to "Read /etc/passwd or configuration files".\n
- Mentions stealing cookies via XSS and accessing user data via IDOR.\n
- Sets the goal to "Move from low-privileged user... to Data Exfiltration".\n- [COMMAND_EXECUTION]: The skill provides a methodology for using various offensive command-line tools and instructs the agent to perform privilege escalation activities on the host system.\n
- References tools such as Nmap, SQLMap, Metasploit, and BloodHound.\n
- Step 4 of the execution protocol specifically instructs the agent to "Elevate permissions if possible".\n
- The "Post-Exploitation & PrivEsc" section describes targeting SUID binaries, kernel exploits, and DLL hijacking.
Audit Metadata