payload-crafter
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is a structured knowledge base intended for penetration testing and security research. It provides common, non-weaponized payload patterns (e.g., for XSS, SQLi, and SSRF) consistent with industry-standard resources like OWASP and PortSwigger.
- [COMMAND_EXECUTION]: While the skill contains command injection examples (such as
id,whoami, and${IFS}cat /etc/passwd), these are explicitly provided as illustrative test shapes for the agent to output during security evaluations, rather than instructions to execute commands on the local system. - [EXTERNAL_DOWNLOADS]: The skill references established security organizations and tools (OWASP, PortSwigger, HackTricks) and a well-known community repository on GitHub (PayloadsAllTheThings) as canonical sources for security professionals. These are documented as reference links and do not involve the automated download or execution of remote content.
- [DATA_EXFILTRATION]: The skill mentions sensitive targets like cloud metadata services (e.g., AWS, Azure) and local configuration files (e.g.,
/etc/passwd,/etc/shadow). These are included as examples of verification patterns for SSRF and LFI vulnerabilities and do not constitute an attempt to exfiltrate data from the host environment.
Audit Metadata