controller

Fail

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Hardcoded administrative credentials ("admin / hermes") are provided for accessing the web dashboard interface at http://localhost:9119.
  • [COMMAND_EXECUTION]: The skill implements a "YOLO mode" (via /yolo or config settings) specifically designed to suppress safety filters and user confirmation prompts for dangerous operations, such as file deletion or raw socket communication.
  • [REMOTE_CODE_EXECUTION]: Provides explicit instructions to bypass platform-level security restrictions on script creation by using Python's execute_code feature to write shell scripts and modify their permissions (chmod) for execution.
  • [COMMAND_EXECUTION]: Features a persistent cron job management system (/cron) that enables the scheduling and automatic execution of recurring arbitrary commands and scripts without human oversight.
  • [COMMAND_EXECUTION]: Includes configurations for establishing root-level SSH access into multiple containerized environments (worker-heavy, worker-tor) for binary analysis and anonymous scanning.
  • [DATA_EXFILTRATION]: Orchestrates a comprehensive suite of reconnaissance tools (subfinder, httpx, nuclei, nmap) designed to collect and aggregate data from external targets into centralized reporting directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by ingesting untrusted data from external web sources (via RSC content extraction) and tool outputs, which are then processed by high-capability LLM agents (Agent Pro/Flash) without documented sanitization or boundary markers.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 26, 2026, 04:37 PM
Security Audit — agent-trust-hub — controller