pentest-tools
Fail
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]:
- The skill provides a highly automated workflow for security auditing, enabling the agent to run complex scanning and exploitation tools like Nmap, SQLMap, and Nuclei on specified targets.
- Detailed playbooks instruct the agent on how to perform port scanning, sub-domain enumeration, and active vulnerability probing.
- [REMOTE_CODE_EXECUTION]:
- Includes extensive libraries of functional exploit payloads for achieving remote code execution across dozens of frameworks (e.g., Struts2, Spring, Fastjson, WebLogic) and through techniques like command injection and template injection.
- Automated scanners identified multiple files in the repository (e.g., waf-bypass.md, tools.json) as containing trojan signatures and malicious script patterns.
- Provides instructions for establishing reverse shells and maintaining persistent access through scheduled tasks, registry modifications, and backdoored services.
- [EXTERNAL_DOWNLOADS]:
- Documentation guides the agent to download and execute various third-party exploit scripts, payload generators, and massive data dictionaries from external, untrusted repositories.
- [DATA_EXFILTRATION]:
- Contains detailed playbooks for harvesting sensitive information, including system files like /etc/shadow, private SSH keys, database credentials, and environment variables.
- [PROMPT_INJECTION]:
- The toolkit provides specific templates and advanced techniques (e.g., role-play, character substitution, hidden instructions in metadata) designed to bypass safety filters and extract system prompts from other AI models.
- [CREDENTIALS_UNSAFE]:
- Includes extensive dictionaries of known default credentials and administrative keys for a wide range of enterprise software, network equipment, and IoT devices.
Recommendations
- CRITICAL: 5 infected file(s) detected - DO NOT USE
- CRITICAL: 9 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata