hunt-xxe

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's methodology involves the agent processing and analyzing XML responses and error messages from external, untrusted targets. This creates an attack surface where a malicious target could potentially embed instructions in its XML output to influence the agent's behavior. \n
  • Ingestion points: XML responses from mapped endpoints and file upload features as described in SKILL.md. \n
  • Boundary markers: The instructions lack specific delimiters or warnings to ignore embedded instructions within target data. \n
  • Capability inventory: The agent is tasked with reconnaissance, mapping, and documentation of vulnerability impacts. \n
  • Sanitization: No specific sanitization or validation of the untrusted XML content is defined.
  • [DATA_EXFILTRATION]: The skill provides templates for identifying and exfiltrating sensitive system files and cloud metadata. \n
  • Sensitive file paths: The payloads target standard sensitive paths including /etc/passwd, /etc/shadow, C:/Windows/win.ini, and .aws/credentials. \n
  • Network operations: The skill methodology includes instructions for Blind Out-of-Band (OOB) exfiltration targeting external listener servers (e.g., Burp Collaborator or user-controlled HTTP/DNS servers) to capture file contents. This behavior is consistent with the skill's primary purpose as a security research aid.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:31 AM
Security Audit — agent-trust-hub — hunt-xxe