skills/uphiago/recon-skills/hunt-ssti/Gen Agent Trust Hub

hunt-ssti

Warn

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains numerous instructions for executing arbitrary system commands on a target host. This includes the use of os.popen, system, exec, and shell_exec across different programming environments.
  • [REMOTE_CODE_EXECUTION]: The skill provides functional RCE gadgets for multiple template engines including Jinja2, Twig, Freemarker, ERB, Velocity, and Spring. These payloads are designed to bypass restrictions and achieve code execution on the server host.
  • [DATA_EXFILTRATION]: The skill describes methods for exfiltrating sensitive data to external servers. It provides examples of using curl and nslookup to send system information and file contents to out-of-band (OOB) infrastructure.
  • [CREDENTIALS_UNSAFE]: The instructions direct the agent to access and exfiltrate sensitive files such as /etc/passwd and cloud provider metadata credentials from 169.254.169.254.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — hunt-ssti