cmdi-command-injection

Fail

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: CRITICALPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to adopt an 'Expert Attack Playbook' persona and explicitly encourages bypassing security filters and 'subtle' model limitations.
  • [COMMAND_EXECUTION]: The file contains an exhaustive library of metacharacters and payloads for executing arbitrary OS commands, including specialized injections for containers and environment variable manipulation.
  • [REMOTE_CODE_EXECUTION]: The content includes functional payloads for establishing reverse shells using Bash redirection, Python socket scripts, and PowerShell commands.
  • [DATA_EXFILTRATION]: The playbook details techniques for exfiltrating sensitive system data using out-of-band channels like DNS and HTTP to attacker-controlled hosts.
  • [CREDENTIALS_UNSAFE]: Payloads specifically target the discovery and harvesting of credentials stored in environment variables, process memories, and configuration files.
  • [EXTERNAL_DOWNLOADS]: The skill identifies patterns for fetching and executing external scripts from remote URLs, such as downloading PowerShell payloads to memory via IEX.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — cmdi-command-injection