hack
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
install_tools.shscript downloads a compressed binary archive fromreadarr.servarr.comand extracts it directly to the local filesystem without integrity verification. Additionally, thenuclei-updatecommand fetches vulnerability templates from external repositories.\n- [REMOTE_CODE_EXECUTION]: Theexploitcommand incommands.pyfacilitates the execution of arbitrary Python or shell scripts within isolated Docker containers. The 'Chaos Mode' inchaos.pyextends this by using an LLM to generate novel exploit payloads, including Linux x64 assembly code, which are saved to the host and executed in the target environment.\n- [COMMAND_EXECUTION]: The skill extensively usessubprocess.runto execute system commands such asdocker,docker compose, andgit, and to invoke numerous other agent skills on the host system.\n- [DATA_EXFILTRATION]: Thelearncommand incommands.pyfetches data from external sources, including downloading a database from GitLab and cloning repositories from GitHub. These operations interact with external infrastructure to build the skill's knowledge base.\n- [PROMPT_INJECTION]: The skill employs role-playing prompts (e.g., 'senior security researcher') and instructions to 'brainstorm 3 insane or novel exploit ideas' incascade_integration.pyandchaos.py. It also possesses an indirect prompt injection surface:\n - Ingestion points: External exploit databases, GitHub repository content, and tool outputs from nmap, nuclei, and semgrep.\n
- Boundary markers: None identified in the code paths that interpolate untrusted data into LLM prompts.\n
- Capability inventory: Subprocess execution on the host and in containers, local file read/write access, and network operations.\n
- Sanitization: None; data is typically passed as raw strings or JSON into prompts for analysis.
Recommendations
- AI detected serious security threats
Audit Metadata