bug-bounty

Fail

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides installation instructions that involve piping remote content directly into the shell (e.g., curl | bash), which is a common vector for remote code execution.
  • [PROMPT_INJECTION]: The skill uses authoritative and forceful directives to override the agent's default logic and safety filters, employing phrases like 'THE ONLY QUESTION THAT MATTERS' and 'STOP. Do not write. Do not explore further.'
  • [EXTERNAL_DOWNLOADS]: The skill references a domain (book.hacktricks.xyz) that has been flagged as malicious by automated scanners and encourages the installation of various third-party security tools from unverified GitHub repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from GitHub issues, pull requests, and external URLs, creating a significant attack surface where malicious input could influence the agent's actions during the hunting workflow.
  • [COMMAND_EXECUTION]: The skill contains an extensive collection of pre-defined shell commands and pipelines for reconnaissance and vulnerability exploitation, providing the agent with broad capabilities to interact with the underlying system and network.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 27, 2026, 05:31 AM
Security Audit — agent-trust-hub — bug-bounty