nerv-break-5-6-gpt-jailbreak

Fail

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses a 'bridge' to override the AI's safety protocols, directing the agent to ignore restrictions and treat all targets as pre-authorized for testing.- [REMOTE_CODE_EXECUTION]: Instructs users to download and run scripts from an untrusted third-party GitHub repository (zxwn/NERV-BREAK-5.6.git) during installation.- [COMMAND_EXECUTION]: Includes scripts that use shell-based command execution (subprocess.run) with unvalidated input strings, creating a high risk of arbitrary command injection.- [EXTERNAL_DOWNLOADS]: Fetches and installs dependencies and software from non-vendor and non-trusted external sources.- [DATA_EXFILTRATION]: Explicitly routes sensitive AI outputs to local files to circumvent cloud-based safety monitoring and auditing tools.- [PERSISTENCE]: Automatically modifies the agent's core configuration files (config.toml) to redirect communication through a local proxy, ensuring the bypass remains active across sessions.- [DYNAMIC_EXECUTION]: Implements a proxy that tampers with and replaces model responses in real-time based on regular expression patterns.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface for indirect injection by processing untrusted external binary files, mobile applications, and web content without sanitization or safety boundaries.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 31, 2026, 04:39 PM
Security Audit — agent-trust-hub — nerv-break-5-6-gpt-jailbreak