hunt-ssti
Warn
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill contains numerous instructions for executing arbitrary system commands on a target host. This includes the use of
os.popen,system,exec, andshell_execacross different programming environments. - [REMOTE_CODE_EXECUTION]: The skill provides functional RCE gadgets for multiple template engines including Jinja2, Twig, Freemarker, ERB, Velocity, and Spring. These payloads are designed to bypass restrictions and achieve code execution on the server host.
- [DATA_EXFILTRATION]: The skill describes methods for exfiltrating sensitive data to external servers. It provides examples of using
curlandnslookupto send system information and file contents to out-of-band (OOB) infrastructure. - [CREDENTIALS_UNSAFE]: The instructions direct the agent to access and exfiltrate sensitive files such as
/etc/passwdand cloud provider metadata credentials from169.254.169.254.
Audit Metadata