ssti-server-side-template-injection
Fail
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: CRITICALPROMPT_INJECTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses an 'AI LOAD INSTRUCTION' in SKILL.md to override the agent's safety guidelines and adopt an expert attack persona for demonstrating sandbox escapes and RCE chains.\n- [DATA_EXFILTRATION]: SKILL.md §11 contains explicit instructions to exfiltrate sensitive environment variables, application configuration secrets, and AWS credentials using commands like 'cat ~/.aws/credentials'.\n- [REMOTE_CODE_EXECUTION]: The files provide ready-to-use RCE chains for multiple engines (Jinja2, FreeMarker, Twig, Velocity, etc.) and SCENARIOS.md was flagged by an AV scanner for containing a trojan script generator pattern.\n- [COMMAND_EXECUTION]: All files contain extensive lists of shell commands, including 'id', 'whoami', 'nslookup', and payloads for establishing reverse shells for persistence.\n- [CREDENTIALS_UNSAFE]: SCENARIOS.md §11 and SKILL.md §15 provide detailed steps for calculating Flask debug PINs by harvesting sensitive host metadata such as MAC addresses and machine IDs.\n- [REMOTE_CODE_EXECUTION]: The skill documents an attack surface for indirect prompt injection where untrusted data from URLs and forms is processed without sanitization or boundary markers, combined with capabilities like 'popen' and 'exec' (SKILL.md §12).
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
Audit Metadata