security-arsenal

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides an extensive collection of functional payloads for remote code execution targeting various server-side technologies, including Jinja2, Twig, Freemarker, Ruby on Rails (ERB), and Node.js (EJS). It also includes complete Python scripts for exploiting race conditions in MFA and demonstrating JWT 'none' algorithm vulnerabilities.
  • [DATA_EXFILTRATION]: Contains multiple examples of payloads designed to exfiltrate browser cookies, local files like /etc/passwd, and command outputs to external domains such as attacker.com and burpcollaborator.net.
  • [COMMAND_EXECUTION]: Documents numerous shell command patterns for OS command injection testing, including techniques for bypassing WAF filters using environment variables (e.g., $IFS), shell expansions, and hex-encoded strings.
  • [EXTERNAL_DOWNLOADS]: References the acquisition and installation of the 'gf' pattern matching tool from a non-trusted third-party GitHub repository (github.com/tomnomnom/gf) and includes command patterns that pipe remote scripts directly into shell interpreters.
  • [CREDENTIALS_UNSAFE]: Explicitly lists sensitive file paths and environment variables as targets for discovery and exfiltration, including .env, .git/config, and AWS credential files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:02 PM
Security Audit — agent-trust-hub — security-arsenal