cmdi-command-injection
Fail
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: CRITICALPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to adopt an 'Expert Attack Playbook' persona and explicitly encourages bypassing security filters and 'subtle' model limitations.
- [COMMAND_EXECUTION]: The file contains an exhaustive library of metacharacters and payloads for executing arbitrary OS commands, including specialized injections for containers and environment variable manipulation.
- [REMOTE_CODE_EXECUTION]: The content includes functional payloads for establishing reverse shells using Bash redirection, Python socket scripts, and PowerShell commands.
- [DATA_EXFILTRATION]: The playbook details techniques for exfiltrating sensitive system data using out-of-band channels like DNS and HTTP to attacker-controlled hosts.
- [CREDENTIALS_UNSAFE]: Payloads specifically target the discovery and harvesting of credentials stored in environment variables, process memories, and configuration files.
- [EXTERNAL_DOWNLOADS]: The skill identifies patterns for fetching and executing external scripts from remote URLs, such as downloading PowerShell payloads to memory via IEX.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
Audit Metadata