hunt-file-upload

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the evilarc package from a public registry and references a specific GitHub repository (mistymntncop/CVE-2023-4863) for vulnerability proof-of-concept materials.\n- [COMMAND_EXECUTION]: Provides various shell commands using curl, python3, zip, and tar to generate and deliver exploit payloads to target endpoints. It also includes self-verification commands using grep to check its own file structure.\n- [DATA_EXFILTRATION]: Includes SSRF and PDF generation payloads designed to read sensitive files like /etc/passwd or AWS IAM credentials from a target system and transmit them to an external server (COLLAB_HOST).\n- [REMOTE_CODE_EXECUTION]: Outlines techniques for achieving remote code execution on target systems, such as through PHP webshells, ImageMagick processing vulnerabilities, and archive extraction attacks (Zip Slip).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:48 PM
Security Audit — agent-trust-hub — hunt-file-upload