cmdi-command-injection

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONOBFUSCATIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides an extensive library of functional reverse shell payloads for both Linux and Windows environments.
  • Includes Linux payloads using Bash (/dev/tcp redirection), Python (socket and subprocess modules), Netcat (-e and FIFO pipes), and Perl.
  • Includes Windows payloads using PowerShell to download and execute remote scripts (IEX and DownloadString) or establish direct TCP connections.
  • [DATA_EXFILTRATION]: The playbook explicitly teaches how to exfiltrate sensitive data through various channels.
  • Demonstrates Out-of-Band (OOB) exfiltration using DNS lookups (nslookup) and HTTP requests (curl, wget, Invoke-WebRequest).
  • Provides commands to read highly sensitive system files, including /etc/shadow (containing password hashes), /etc/passwd, and environment variables that may hold database credentials or API keys.
  • [COMMAND_EXECUTION]: The skill provides detailed instructions on using shell metacharacters and vulnerable code patterns to execute arbitrary commands on the underlying operating system.
  • Lists common vulnerable patterns in PHP, Python, Node.js, Perl, and ASP.
  • Details the use of injection operators such as ;, |, &&, and backticks to break out of intended command contexts.
  • [OBFUSCATION]: Multiple techniques are documented to hide malicious intent and bypass security filters.
  • Demonstrates space alternatives like ${IFS} and brace expansion {cat,/etc/passwd}.
  • Includes keyword bypass methods using variable assembly (e.g., a=c;b=at; $a$b) and character escapes.
  • Details PHP-specific obfuscation using XOR string construction, ROT13, and Base64-encoded function names to evade static analysis.
  • [DYNAMIC_EXECUTION]: The skill documents how to exploit dynamic execution sinks in various languages.
  • Targets PHP's eval(), exec(), and shell_exec().
  • Targets Python's os.system() and subprocess.call(..., shell=True).
  • Targets Node.js's child_process.exec().
  • [PRIVILEGE_ESCALATION]: Includes methods to gain higher privileges or break out of restricted environments.
  • Describes techniques for container breakout via kubectl exec and docker exec injection.
  • Details environment variable injection (e.g., LD_PRELOAD, BASH_ENV) to achieve execution during process startup.
Recommendations
  • CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 02:14 PM
Security Audit — agent-trust-hub — cmdi-command-injection