File Path Traversal Testing
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill provides instructions to target and access files containing highly sensitive credentials. Examples include Linux password hashes (
/etc/shadow), SSH private keys (/root/.ssh/id_rsa,~/.ssh/id_rsa), and Windows Security Account Manager (SAM) database files (C:\windows\system32\config\SAM). - [REMOTE_CODE_EXECUTION]: Detailed methodologies for achieving code execution are included. This involves log poisoning techniques (injecting PHP shell commands into server access or authentication logs via HTTP headers) and the exploitation of PHP wrappers such as
expect://,php://input, anddata://to execute commands on the remote host. - [DATA_EXFILTRATION]: The skill's primary focus is the extraction of arbitrary files from a server. Targeted data includes environment variables (
/proc/self/environ), database credentials in web configuration files (wp-config.php,config.php), and system configuration files. - [COMMAND_EXECUTION]: The core workflow relies on the execution of shell commands using tools like
curl,ffuf, andwfuzzto send payloads and interact with external targets. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a vulnerability surface where the agent processes untrusted data from external URLs and parameters. It lacks boundary markers or sanitization logic, which could lead the agent to interpret embedded instructions within the data it is analyzing.
Recommendations
- AI detected serious security threats
Audit Metadata