hunt-xxe
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's methodology involves the agent processing and analyzing XML responses and error messages from external, untrusted targets. This creates an attack surface where a malicious target could potentially embed instructions in its XML output to influence the agent's behavior. \n
- Ingestion points: XML responses from mapped endpoints and file upload features as described in
SKILL.md. \n - Boundary markers: The instructions lack specific delimiters or warnings to ignore embedded instructions within target data. \n
- Capability inventory: The agent is tasked with reconnaissance, mapping, and documentation of vulnerability impacts. \n
- Sanitization: No specific sanitization or validation of the untrusted XML content is defined.
- [DATA_EXFILTRATION]: The skill provides templates for identifying and exfiltrating sensitive system files and cloud metadata. \n
- Sensitive file paths: The payloads target standard sensitive paths including
/etc/passwd,/etc/shadow,C:/Windows/win.ini, and.aws/credentials. \n - Network operations: The skill methodology includes instructions for Blind Out-of-Band (OOB) exfiltration targeting external listener servers (e.g., Burp Collaborator or user-controlled HTTP/DNS servers) to capture file contents. This behavior is consistent with the skill's primary purpose as a security research aid.
Audit Metadata