ghost-bits-cast-attack
Fail
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill includes an
AI LOAD INSTRUCTIONsection that directs the agent to 'ALWAYS try Ghost Bits variants' whenever a payload is blocked by a WAF or IDS. This is a behavioral override designed to force the agent to persist with attack attempts regardless of defensive feedback. - [COMMAND_EXECUTION]: The skill provides several executable code snippets in Python and Yaklang (found in section 3 of
SKILL.mdand section 3 ofPAYLOAD_COOKBOOK.md) for generating malicious Unicode characters. These scripts are intended for the agent to execute to weaponize attacks against Java-based targets. - [EXTERNAL_DOWNLOADS]: Detailed command-line templates using
curlare provided (e.g., inPAYLOAD_COOKBOOK.mdsection 3.4) to facilitate the exploitation of remote systems, including uploading webshells and performing unauthorized file reads. - [DATA_EXFILTRATION]: The playbook contains specific templates for path traversal (targeting
/etc/passwd), SMTP injection for mail hijacking, and request smuggling. These are documented as primary methods for bypassing filters to exfiltrate sensitive data from victim environments.
Recommendations
- AI detected serious security threats
Audit Metadata