skills/grahama1970/agent-skills/hack/Gen Agent Trust Hub

hack

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The install_tools.sh script downloads a compressed binary archive from readarr.servarr.com and extracts it directly to the local filesystem without integrity verification. Additionally, the nuclei-update command fetches vulnerability templates from external repositories.\n- [REMOTE_CODE_EXECUTION]: The exploit command in commands.py facilitates the execution of arbitrary Python or shell scripts within isolated Docker containers. The 'Chaos Mode' in chaos.py extends this by using an LLM to generate novel exploit payloads, including Linux x64 assembly code, which are saved to the host and executed in the target environment.\n- [COMMAND_EXECUTION]: The skill extensively uses subprocess.run to execute system commands such as docker, docker compose, and git, and to invoke numerous other agent skills on the host system.\n- [DATA_EXFILTRATION]: The learn command in commands.py fetches data from external sources, including downloading a database from GitLab and cloning repositories from GitHub. These operations interact with external infrastructure to build the skill's knowledge base.\n- [PROMPT_INJECTION]: The skill employs role-playing prompts (e.g., 'senior security researcher') and instructions to 'brainstorm 3 insane or novel exploit ideas' in cascade_integration.py and chaos.py. It also possesses an indirect prompt injection surface:\n
  • Ingestion points: External exploit databases, GitHub repository content, and tool outputs from nmap, nuclei, and semgrep.\n
  • Boundary markers: None identified in the code paths that interpolate untrusted data into LLM prompts.\n
  • Capability inventory: Subprocess execution on the host and in containers, local file read/write access, and network operations.\n
  • Sanitization: None; data is typically passed as raw strings or JSON into prompts for analysis.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — hack