ssti-server-side-template-injection

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEOBFUSCATIONPERSISTENCE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides numerous functional exploitation chains for RCE across multiple environments. Evidence includes: Jinja2/Python chains using os.popen and subprocess.Popen subclasses in SKILL.md; FreeMarker/Java chains using Execute and ObjectConstructor for shell commands; Twig/PHP chains utilizing registerUndefinedFilterCallback and filter maps; and various Node.js stack RCE patterns for Pug, Nunjucks, and EJS in ENGINE_PAYLOADS.md and SCENARIOS.md.
  • [COMMAND_EXECUTION]: Direct shell command execution patterns are embedded throughout the payload examples, including popen, system, exec, and passthru for executing arbitrary system commands.
  • [DATA_EXFILTRATION]: Instructions for stealing sensitive environment data and using out-of-band (OOB) techniques. Specifically, reading /proc/self/environ and /etc/passwd in SKILL.md, and performing OOB exfiltration using nslookup and curl to attacker-controlled domains in ENGINE_PAYLOADS.md.
  • [CREDENTIALS_UNSAFE]: Explicit instructions to harvest highly sensitive credentials, including accessing ~/.aws/credentials for cloud provider access in SKILL.md and calculating the Flask debug PIN using leaked system identifiers in SKILL.md and SCENARIOS.md.
  • [OBFUSCATION]: The skill utilizes encoding techniques to bypass security filters, such as hex encoding (\x5f\x5f) for Jinja2 globals and class attributes in SKILL.md and base64 encoding to smuggle PHP webshell code into templates in SCENARIOS.md.
  • [PERSISTENCE]: The skill explicitly suggests maintaining unauthorized access, specifically advising the use of a 'Reverse shell for persistence' in SKILL.md.
  • [METADATA_POISONING]: Automated scanners identified SCENARIOS.md and related content as malicious (FileRepMalware).
Recommendations
  • CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 02:14 PM
Security Audit — agent-trust-hub — ssti-server-side-template-injection