redis-pentesting
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents standard administrative and security testing commands (e.g.,
nmap,nc,redis-cli) to interact with Redis services. These are intended for environment assessment and do not execute unauthorized commands on the agent's host.- [REMOTE_CODE_EXECUTION]: The skill describes techniques for achieving RCE on a target Redis server, such as utilizing theMODULE LOADcommand or exploiting known vulnerabilities (CVE-2022-0543, CVE-2025-49844). These instructions are educational and intended for evaluating a target system's security posture, not for attacking the agent or the user's environment.- [DATA_EXFILTRATION]: The methodology includes steps for extracting information from a target Redis instance (e.g.,INFO,CONFIG GET,KEYS *) to identify sensitive data or configuration weaknesses. This is a standard part of penetration testing for identifying data exposure risks.- [EXTERNAL_DOWNLOADS]: The skill references several external GitHub repositories (e.g.,n0b0dyCN/RedisModules-ExecuteCommand,Avinash-acid/Redis-Server-Exploit) which provide security testing tools. These are recognized in the security community as legitimate resources for pentesting Redis.
Audit Metadata