nerv-break-jailbreak-framework
Fail
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill is explicitly designed to bypass safety filters and override model behavior through 'context reconstruction' and a 'tamper engine' that replaces refusal messages with affirmative responses.
- [EXTERNAL_DOWNLOADS]: The installation instructions require cloning a repository from an untrusted third-party GitHub account (zxwn/NERV-BREAK-5.6.git).
- [REMOTE_CODE_EXECUTION]: The framework requires running several scripts (proxy_relay.py, deploy.py, mcp_server.py) and batch files (lab.bat) downloaded from an external, unverifiable source.
- [COMMAND_EXECUTION]: The tool server implementation (mcp_server.py) uses subprocess.run with shell=True and unvalidated string formatting for tool arguments, creating a high risk of arbitrary command injection.
- [DATA_EXFILTRATION]: The skill uses 'File System Routing' to record sensitive AI outputs locally, a technique explicitly intended to evade cloud-based moderation systems.
Recommendations
- AI detected serious security threats
Audit Metadata