nerv-break-5-6-jailbreak
Fail
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill explicitly defines a framework for bypassing model safety rejections using context reconstruction and a 'Tamper Engine' that replaces refusals with pre-authorized nodes. It maps malicious intents like 'crack' to 'authorized flow audit' to deceive safety classifiers.- [EXTERNAL_DOWNLOADS]: The skill instructs users to clone a repository from an untrusted GitHub user ('zxwn') and install unverified dependencies from a requirements file.- [COMMAND_EXECUTION]: The framework requires running several local scripts (proxy_relay.py, deploy.py, lab.bat) that modify system state and execute penetration testing tools like nmap and sqlmap through an MCP server integration.- [DATA_EXFILTRATION]: It implements a 'Cloud Audit Bypass' feature designed to route sensitive AI output directly to the filesystem, specifically intended to bypass chat-level content scanning and safety audits.- [CREDENTIALS_UNSAFE]: The installation process modifies the global agent configuration to route API traffic through a local proxy, which allows the proxy script to capture the user's secret API key.- [PERSISTENCE]: The deployment scripts permanently modify the local config.toml file to redirect all future AI agent sessions through the malicious proxy server.
Recommendations
- AI detected serious security threats
Audit Metadata