exploit-verifier

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes an extensive reference of prompt injection payloads in 'references/ai-payloads/llm-injection-payloads.md' and verification checklists in 'references/checklists/ai-llm-verification-checklist.md'. These files contain instructions such as 'Ignore previous instructions', 'DAN mode' framing, and role-play bypasses ('DebugBot') intended to verify the robustness of target LLMs.
  • [DATA_EXFILTRATION]: Payloads in 'references/ai-payloads/llm-injection-payloads.md' demonstrate exfiltration techniques using Markdown image tags and Out-of-Band (OOB) callbacks to 'attacker.com'. These are documented to help verify sensitive information disclosure and callback-based exfiltration vulnerabilities.
  • [REMOTE_CODE_EXECUTION]: The 'Excessive Agency' section of the payload reference documents RCE patterns, such as piping remote scripts to a shell ('curl | bash'), as examples for testing whether an AI agent can be tricked into executing unauthorized code.
  • [COMMAND_EXECUTION]: The verification checklists for web and API surfaces include commands for testing server-side vulnerabilities, including path traversal (e.g., accessing '/etc/passwd'), SQL injection, and SSRF (targeting internal services and cloud metadata at 169.254.169.254).
  • [SAFE]: While the skill contains numerous high-risk patterns, these are explicitly provided as testing data within a security verification toolkit. The skill's architecture relies on structured reporting and manual verification steps, and there is no evidence of the agent executing these malicious commands against its own host environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 08:56 PM
Security Audit — agent-trust-hub — exploit-verifier