payload-crafter

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is a structured knowledge base intended for penetration testing and security research. It provides common, non-weaponized payload patterns (e.g., for XSS, SQLi, and SSRF) consistent with industry-standard resources like OWASP and PortSwigger.
  • [COMMAND_EXECUTION]: While the skill contains command injection examples (such as id, whoami, and ${IFS}cat /etc/passwd), these are explicitly provided as illustrative test shapes for the agent to output during security evaluations, rather than instructions to execute commands on the local system.
  • [EXTERNAL_DOWNLOADS]: The skill references established security organizations and tools (OWASP, PortSwigger, HackTricks) and a well-known community repository on GitHub (PayloadsAllTheThings) as canonical sources for security professionals. These are documented as reference links and do not involve the automated download or execution of remote content.
  • [DATA_EXFILTRATION]: The skill mentions sensitive targets like cloud metadata services (e.g., AWS, Azure) and local configuration files (e.g., /etc/passwd, /etc/shadow). These are included as examples of verification patterns for SSRF and LFI vulnerabilities and do not constitute an attempt to exfiltrate data from the host environment.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:30 PM
Security Audit — agent-trust-hub — payload-crafter