security-payloads
Fail
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: CRITICAL
Full Analysis
- [SAFE]: The skill includes the EICAR Standard Anti-Virus Test File (references/Payloads/Anti-Virus/eicar-com.txt), which is a non-malicious string used globally by security professionals to verify that antivirus software is active and correctly configured. This explains the detection in the automated scan.
- [SAFE]: Filename examples provided in the references/Payloads/File-Names/ directory, such as those containing null bytes (%00) or command injection syntax ($(hostname)), are static payload strings intended for testing file upload vulnerabilities and are not executed by the agent.
- [SAFE]: The skill provides a Flash-based proof-of-concept file (references/Payloads/Flash/xssproject.swf) for testing Cross-Site Scripting (XSS) vulnerabilities, consistent with its stated purpose as a security research tool.
- [SAFE]: All content and references are transparently sourced from the well-known SecLists open-source project, and no evidence of malicious behavior, obfuscation, or unauthorized data access was found.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
Audit Metadata