hunting-web-backdoors

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to fetch public advisories and documentation through defuddle.md. This third-party service is used as a proxy to extract Markdown content from URLs, which involves fetching content from an external domain not recognized as a standard trusted source.- [DATA_EXFILTRATION]: By recommending the use of a Markdown extraction proxy (defuddle.md), the skill inherently suggests sending URLs to a third-party service. While it includes specific warnings against routing sensitive infrastructure or adversary-controlled URLs through this service, the pattern represents a potential data exposure vector if instructions are not strictly followed.- [PROMPT_INJECTION]: The skill's primary function is to ingest and analyze untrusted, potentially malicious data from a compromised web root (e.g., PHP files, plugins). This creates a surface for indirect prompt injection where the agent might encounter and process adversarial instructions embedded in the audited code. The skill mitigates this risk with clear boundaries, instructing the agent to treat findings as payloads and to perform static deobfuscation without execution.- [DATA_EXFILTRATION]: The skill uses intentional character insertion (ev[a]l, ass[e]rt) to bypass automated security scanners (antivirus false positives). While these patterns are described as a defensive necessity for the skill's distribution, they demonstrate knowledge of and implementation of signature-evasion techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:30 AM
Security Audit — agent-trust-hub — hunting-web-backdoors