payloads-reverse-shells

Warn

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONOBFUSCATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill contains a collection of one-line payloads for establishing reverse shell connections from a compromised host to an external listener. It provides templates for Bash, Python, PHP, Perl, Ruby, Node.js, Java, Groovy, and Lua environments.\n- [COMMAND_EXECUTION]: Includes specific instructions and command-line arguments for running listeners using tools such as Netcat (nc), socat, and pwncat-cs. It also provides commands for using msfvenom to generate malicious binary payloads for Linux, Windows, and Java platforms.\n- [DATA_EXFILTRATION]: The provided shell payloads connect to a user-specified attacker IP and port ($LHOST/$LPORT), creating a bidirectional communication channel that allows for remote command execution and exfiltration of sensitive information.\n- [DYNAMIC_EXECUTION]: Many payloads utilize dynamic execution features of their respective languages, such as python -c, powershell -c (with Invoke-Expression/iex), and PHP's system/exec functions to process and run arbitrary command strings.\n- [OBFUSCATION]: The skill explicitly discusses methods for evading security filters and Web Application Firewalls (WAFs), specifically recommending the use of Base64 encoding for PowerShell payloads and URL encoding for web-based injections.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 26, 2026, 02:01 AM
Security Audit — agent-trust-hub — payloads-reverse-shells