ctf-web
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONOBFUSCATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references a missing shell script
scripts/install_ctf_tools.shfor tool setup and explicitly instructs the agent to clone thePayloadsAllTheThingsrepository from GitHub. - [PROMPT_INJECTION]: Multiple markdown files (e.g.,
auth-and-access.md) contain explicit instructions and payloads for jailbreaking AI chatbots, including "System Override" and "Ignore previous instructions" patterns. While intended for target systems, these may interfere with the agent's own constraints. - [COMMAND_EXECUTION]: The skill includes a functional Python fuzzer (
scripts/async_fuzz.py) and various command snippets for network reconnaissance and exploitation. - [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves ingesting large quantities of untrusted data from external repositories and target responses, which lack boundary markers to prevent accidental instruction execution.
- [OBFUSCATION]: Documentation in
pat-reference.mdincludes examples of URL-encoded dots (%2e) used to bypass redirection filters, which are flagged as a technique for concealing destination targets.
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
- CRITICAL: 1 obfuscated URL(s) are MALICIOUS: https://example.com.attacker.example.com/ - DO NOT USE
Audit Metadata