skills/ljagiello/ctf-skills/ctf-web/Gen Agent Trust Hub

ctf-web

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONOBFUSCATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a missing shell script scripts/install_ctf_tools.sh for tool setup and explicitly instructs the agent to clone the PayloadsAllTheThings repository from GitHub.
  • [PROMPT_INJECTION]: Multiple markdown files (e.g., auth-and-access.md) contain explicit instructions and payloads for jailbreaking AI chatbots, including "System Override" and "Ignore previous instructions" patterns. While intended for target systems, these may interfere with the agent's own constraints.
  • [COMMAND_EXECUTION]: The skill includes a functional Python fuzzer (scripts/async_fuzz.py) and various command snippets for network reconnaissance and exploitation.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves ingesting large quantities of untrusted data from external repositories and target responses, which lack boundary markers to prevent accidental instruction execution.
  • [OBFUSCATION]: Documentation in pat-reference.md includes examples of URL-encoded dots (%2e) used to bypass redirection filters, which are flagged as a technique for concealing destination targets.
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
  • CRITICAL: 1 obfuscated URL(s) are MALICIOUS: https://example.com.attacker.example.com/ - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 04:50 AM
Security Audit — agent-trust-hub — ctf-web