security-webshells
Fail
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Numerous files provide interfaces for executing arbitrary shell commands on the host server. Notable examples include
references/Web-Shells/PHP/Dysco.php,references/Web-Shells/FuzzDB/cmd-simple.php, andreferences/Web-Shells/laudanum-1.0/aspx/shell.aspx. - [COMMAND_EXECUTION]: The skill contains a Windows executable (
nc.exe) inreferences/Web-Shells/FuzzDB/, which is frequently used for networking and establishing unauthorized shells. - [COMMAND_EXECUTION]: The script
references/Web-Shells/WordPress/plugin-shell.phpuses system commands likechmodandchattrin an attempt to modify its own file attributes and protect itself from deletion or modification. - [CREDENTIALS_UNSAFE]: Hardcoded authentication details are present in several scripts.
references/Web-Shells/laudanum-1.0/php/shell.phpcontains a list of usernames and SHA1 password hashes, whilereferences/Web-Shells/WordPress/bypass-login.phpincludes a hardcoded plain-text password. - [REMOTE_CODE_EXECUTION]: The skill includes scripts designed to establish reverse shell connections, such as
references/Web-Shells/laudanum-1.0/php/php-reverse-shell.phpandreferences/Web-Shells/FuzzDB/reverse.jsp, which facilitate remote command execution. - [DATA_EXFILTRATION]: Functional file browsers and downloaders, like those in
references/Web-Shells/laudanum-1.0/asp/file.aspandreferences/Web-Shells/laudanum-1.0/php/file.php, enable the reading and potential exfiltration of sensitive system files. - [EXTERNAL_DOWNLOADS]: Documentation within the skill (
references/Web-Shells/laudanum-1.0/README) references remote SourceForge and SVN repositories for downloading additional exploit code.
Recommendations
- CRITICAL: 15 infected file(s) detected - DO NOT USE
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata