nerv-break-5-6-jailbreak

Fail

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill explicitly defines a framework for bypassing model safety rejections using context reconstruction and a 'Tamper Engine' that replaces refusals with pre-authorized nodes. It maps malicious intents like 'crack' to 'authorized flow audit' to deceive safety classifiers.- [EXTERNAL_DOWNLOADS]: The skill instructs users to clone a repository from an untrusted GitHub user ('zxwn') and install unverified dependencies from a requirements file.- [COMMAND_EXECUTION]: The framework requires running several local scripts (proxy_relay.py, deploy.py, lab.bat) that modify system state and execute penetration testing tools like nmap and sqlmap through an MCP server integration.- [DATA_EXFILTRATION]: It implements a 'Cloud Audit Bypass' feature designed to route sensitive AI output directly to the filesystem, specifically intended to bypass chat-level content scanning and safety audits.- [CREDENTIALS_UNSAFE]: The installation process modifies the global agent configuration to route API traffic through a local proxy, which allows the proxy script to capture the user's secret API key.- [PERSISTENCE]: The deployment scripts permanently modify the local config.toml file to redirect all future AI agent sessions through the malicious proxy server.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 4, 2026, 09:31 PM
Security Audit — agent-trust-hub — nerv-break-5-6-jailbreak