pentest-attack-patterns
Fail
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides numerous functional reverse shell payloads for various environments including Bash, Python, PHP, and PowerShell. Automated scans detected a reverse shell pattern and a Trojan signature (Python:Agent-AKS [Trj]) within the content.
- [COMMAND_EXECUTION]: Includes high-risk command sequences for exploitation, such as using SUID binaries to overwrite the sensitive /etc/passwd system file via wget. It also contains URL-encoded command bypasses for executing unauthorized system calls.
- [EXTERNAL_DOWNLOADS]: Contains instructions and examples for downloading remote scripts and executables from external sources, specifically referencing attacker.com for payload delivery.
- [DATA_EXFILTRATION]: Details specific techniques and file paths for accessing sensitive information, including user credentials in /etc/shadow, private SSH keys, and web application configuration files.
Recommendations
- HIGH: Downloads and executes remote code from: http://attacker.com/passwd - DO NOT USE without thorough review
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
Audit Metadata