upload-insecure-files
Fail
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documents numerous techniques and provides specific payloads to achieve remote code execution on target systems. This includes the use of PHP and JSP webshells (e.g., <%eval request("cmd")%>), ImageTragick delegate abuse payloads, and Ghostscript sandbox escapes. These are presented as reference material for security testing.
- [COMMAND_EXECUTION]: The playbook lists various shell commands for the agent to use when generating malicious files or testing server responses, such as using exiftool to embed PHP code in image metadata or curl to exploit PUT method vulnerabilities.
- [DATA_EXFILTRATION]: Instructions are provided for exploiting local file disclosure and SSRF vulnerabilities through media processors. This includes the use of malicious M3U8 (HLS) playlists to read local files like /etc/passwd or query cloud metadata endpoints.
Recommendations
- CRITICAL: 2 infected file(s) detected - DO NOT USE
- CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata