capability-primitive-search

Warn

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides an adversarial reasoning framework that instructs the agent to bypass safety constraints and mindset limitations (e.g., instructions to 'break inherent thinking' regarding unexploitable systems) in order to hunt for attack primitives.
  • [PROMPT_INJECTION]: It contains explicit templates for achieving Remote Code Execution (RCE) by chaining capabilities such as file writes, configuration manipulation, and credential harvesting.
  • [PROMPT_INJECTION]: The instructions describe specific techniques for bypassing security validation, including protocol jumping (SSRF to Gopher/Redis), character encoding, and exploiting parsing differences between reverse proxies and application servers.
  • [PROMPT_INJECTION]: The skill directs the agent to target sensitive system files and persistence mechanisms, including ~/.ssh/authorized_keys, LD_PRELOAD, crontab, and environment variables for the purpose of maintaining unauthorized access.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 31, 2026, 01:37 AM
Security Audit — agent-trust-hub — capability-primitive-search