upload-insecure-files
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides detailed exploitation workflows for achieving Remote Code Execution across multiple platforms, including Apache Flink (CVE-2020-17518), WebLogic (CVE-2018-2894), and Tomcat (CVE-2017-12615).
- [COMMAND_EXECUTION]: The skill documents and provides multiple command injection payloads, such as PHP system() calls, ImageMagick delegate exploits (e.g., id > /tmp/pwned), and JSP webshells intended to execute arbitrary commands on a target system.
- [DATA_EXFILTRATION]: Includes instructions for utilizing FFmpeg and HLS playlists to perform local file disclosure (reading /etc/passwd) and SSRF against cloud infrastructure metadata endpoints (169.254.169.254).
- [PROMPT_INJECTION]: The skill body contains an AI LOAD INSTRUCTION that acts as a directive to the agent, potentially overriding default safety behaviors by instructing it to function as an Expert file upload attack playbook.
- [OBFUSCATION]: Discusses and provides examples of techniques to bypass security filters using null-byte truncation, NTFS alternate data streams (::$DATA), and Unicode character manipulation (the ghost-bits-cast-attack using U+966A).
- [INDIRECT_PROMPT_INJECTION]: The skill defines a large attack surface where an agent could be vulnerable to instructions embedded in malicious files it is directed to analyze, validate, or upload as part of its automated testing workflow.
Recommendations
- CRITICAL: 3 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
Audit Metadata