jarvis-sec
Warn
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a custom CLI
jarvis-secthat executes a wide range of security testing operations, including vulnerability scanning, exploitation, and credential attacks. It also includes offensive modules for lateral movement in Active Directory and persistence in post-exploitation phases. - [EXTERNAL_DOWNLOADS]: The skill references an installation script
install_tools.shthat downloads and installs 48 external security tools and wordlists via Homebrew, pip, and Go from various third-party sources, including the Z4nzu/hackingtool and SecLists repositories. - [DATA_EXFILTRATION]: The
post_exploitagent is explicitly designed to perform data exfiltration and command-and-control (C2) operations, which are documented as core features of the offensive security toolkit. - [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by processing external data from potentially attacker-controlled sources such as URLs, forensics files, and malware samples. \n- Ingestion points: File paths and URLs provided to agents (e.g.,
jarvis-sec web <url>,jarvis-sec forensics <file>). \n- Boundary markers: None identified in the provided instructions. \n- Capability inventory: Extensive system capabilities including shell execution, network access, and file system modification across 14 agents. \n- Sanitization: No evidence of input validation or content sanitization is present in the skill instructions.
Audit Metadata