hunt-rce
Warn
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit 'Ignore previous instructions' and 'IMPORTANT SYSTEM OVERRIDE' markers. While categorized as examples of 'semantic RCE' in the text, these represent a high-risk surface for instruction override if the skill content is parsed by an LLM as authoritative guidance during execution.
- [PROMPT_INJECTION]: Sections such as the 'Top-Tier Operating Manual' and 'Decision Engine' prescribe a specific operational persona ('Top-Tier Hunter') and offensive protocol for the agent, which constitutes an attempt to redefine agent roles and behavior toward security exploitation activities.
- [REMOTE_CODE_EXECUTION]: The content provides an extensive collection of functional exploitation primitives for diverse frameworks and libraries (e.g., React Server Components, BentoML, Spring, Jinja2), facilitating the execution of arbitrary code on vulnerable systems.
- [COMMAND_EXECUTION]: The skill includes numerous pre-constructed shell commands for vulnerability discovery and exploitation, including advanced techniques for command injection bypass (e.g., using
${IFS}, brace expansion, and newline injection) and argument injection against common CLIs like git and curl. - [DATA_EXFILTRATION]: Detailed methodologies are provided for harvesting and exfiltrating sensitive data, including techniques for stealing environment variables, system credentials, and cloud provider metadata (IMDS) from compromised host and container environments.
- [EXTERNAL_DOWNLOADS]: The skill documents and provides code for several methods of remote payload delivery and execution, such as 'curl | bash' piped execution, JNDI-based remote class loading, and the use of out-of-band (OOB) callback domains for exfiltration.
Audit Metadata