postgresql-pentesting
Fail
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: CRITICALCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill contains multiple functional payloads for achieving remote code execution. This includes Perl and C-based reverse shells, and instructions to download and execute arbitrary scripts via shell pipes (e.g.,
curl | bash). Automated scanners confirmed the presence of malicious patterns and a Trojan (Agent-BKA) in the documentation. - [COMMAND_EXECUTION]: The skill facilitates the execution of offensive security tools (Nmap, Metasploit, Hydra) and details how to use database functions to write and compile malicious binary extensions on the host system.
- [DATA_EXFILTRATION]: The skill includes instructions to exfiltrate database contents and system files to external servers using
curlanddblink. - [EXTERNAL_DOWNLOADS]: The skill directs the agent to download scripts from attacker-controlled domains and suggests the use of third-party tools from unverified GitHub repositories.
- [CREDENTIALS_UNSAFE]: The skill contains automated routines to access and extract sensitive authentication data, including
~/.pgpass,pg_shadow, andpg_authidfiles.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
Audit Metadata