hunt-file-upload
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
evilarcpackage from a public registry and references a specific GitHub repository (mistymntncop/CVE-2023-4863) for vulnerability proof-of-concept materials.\n- [COMMAND_EXECUTION]: Provides various shell commands usingcurl,python3,zip, andtarto generate and deliver exploit payloads to target endpoints. It also includes self-verification commands usinggrepto check its own file structure.\n- [DATA_EXFILTRATION]: Includes SSRF and PDF generation payloads designed to read sensitive files like/etc/passwdor AWS IAM credentials from a target system and transmit them to an external server (COLLAB_HOST).\n- [REMOTE_CODE_EXECUTION]: Outlines techniques for achieving remote code execution on target systems, such as through PHP webshells, ImageMagick processing vulnerabilities, and archive extraction attacks (Zip Slip).
Audit Metadata