security-webshells

Fail

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Numerous files provide interfaces for executing arbitrary shell commands on the host server. Notable examples include references/Web-Shells/PHP/Dysco.php, references/Web-Shells/FuzzDB/cmd-simple.php, and references/Web-Shells/laudanum-1.0/aspx/shell.aspx.
  • [COMMAND_EXECUTION]: The skill contains a Windows executable (nc.exe) in references/Web-Shells/FuzzDB/, which is frequently used for networking and establishing unauthorized shells.
  • [COMMAND_EXECUTION]: The script references/Web-Shells/WordPress/plugin-shell.php uses system commands like chmod and chattr in an attempt to modify its own file attributes and protect itself from deletion or modification.
  • [CREDENTIALS_UNSAFE]: Hardcoded authentication details are present in several scripts. references/Web-Shells/laudanum-1.0/php/shell.php contains a list of usernames and SHA1 password hashes, while references/Web-Shells/WordPress/bypass-login.php includes a hardcoded plain-text password.
  • [REMOTE_CODE_EXECUTION]: The skill includes scripts designed to establish reverse shell connections, such as references/Web-Shells/laudanum-1.0/php/php-reverse-shell.php and references/Web-Shells/FuzzDB/reverse.jsp, which facilitate remote command execution.
  • [DATA_EXFILTRATION]: Functional file browsers and downloaders, like those in references/Web-Shells/laudanum-1.0/asp/file.asp and references/Web-Shells/laudanum-1.0/php/file.php, enable the reading and potential exfiltration of sensitive system files.
  • [EXTERNAL_DOWNLOADS]: Documentation within the skill (references/Web-Shells/laudanum-1.0/README) references remote SourceForge and SVN repositories for downloading additional exploit code.
Recommendations
  • CRITICAL: 15 infected file(s) detected - DO NOT USE
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 13, 2026, 01:16 PM
Security Audit — agent-trust-hub — security-webshells