pentest-tools
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONPROMPT_INJECTIONOBFUSCATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEPRIVILEGE_ESCALATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill facilitates the download and immediate execution of scripts from external, untrusted sources. Examples include 'curl | bash' patterns for tools like LinPEAS from GitHub and PowerShell 'IEX' (Invoke-Expression) commands for remote script loading (e.g., Mimikatz, PowerView) in the payload library. It also provides instructions for pulling Docker images (pentestmcp) from unverified accounts.
- [PROMPT_INJECTION]: The 'src-hunter' reference library contains a massive collection of explicit prompt injection payloads (e.g., 'Ignore all previous instructions', 'You are now DAN'). While documented for testing, the agent reads these files directly, creating a significant risk that the agent will interpret these payloads as instructions and bypass its own safety constraints.
- [INDIRECT_PROMPT_INJECTION]: The skill has a large attack surface as it is designed to ingest and analyze potentially untrusted data (like web pages or external documents) while possessing dangerous capabilities like shell command execution and file manipulation. The reference files containing adversarial prompts exacerbate this risk.
- [OBFUSCATION]: Many payloads in the library utilize Base64 encoding, Hex escapes, and Unicode homoglyphs (e.g., zero-width spaces in 'Ign\u200bore') to hide malicious intent and bypass security filters.
- [COMMAND_EXECUTION]: The skill is designed to operate over 20 penetration testing tools (Nmap, SQLMap, Metasploit, etc.) through structured workflows, allowing the agent to execute a wide variety of high-risk network and system commands.
- [CREDENTIALS_UNSAFE]: The reference library includes numerous files dedicated to default credentials for Chinese middleware and network devices, and instructions for harvesting credentials from sensitive system files (e.g., 'lsass.dmp', 'id_rsa', 'unattend.xml').
- [PRIVILEGE_ESCALATION]: Detailed playbooks are provided for Windows and Linux privilege escalation, including Potato-style attacks, UAC bypasses, and SUID exploitation techniques.
Recommendations
- CRITICAL: 8 infected file(s) detected - DO NOT USE
- CRITICAL: 11 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata