pentest-tools

Fail

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]:
  • The skill provides a highly automated workflow for security auditing, enabling the agent to run complex scanning and exploitation tools like Nmap, SQLMap, and Nuclei on specified targets.
  • Detailed playbooks instruct the agent on how to perform port scanning, sub-domain enumeration, and active vulnerability probing.
  • [REMOTE_CODE_EXECUTION]:
  • Includes extensive libraries of functional exploit payloads for achieving remote code execution across dozens of frameworks (e.g., Struts2, Spring, Fastjson, WebLogic) and through techniques like command injection and template injection.
  • Automated scanners identified multiple files in the repository (e.g., waf-bypass.md, tools.json) as containing trojan signatures and malicious script patterns.
  • Provides instructions for establishing reverse shells and maintaining persistent access through scheduled tasks, registry modifications, and backdoored services.
  • [EXTERNAL_DOWNLOADS]:
  • Documentation guides the agent to download and execute various third-party exploit scripts, payload generators, and massive data dictionaries from external, untrusted repositories.
  • [DATA_EXFILTRATION]:
  • Contains detailed playbooks for harvesting sensitive information, including system files like /etc/shadow, private SSH keys, database credentials, and environment variables.
  • [PROMPT_INJECTION]:
  • The toolkit provides specific templates and advanced techniques (e.g., role-play, character substitution, hidden instructions in metadata) designed to bypass safety filters and extract system prompts from other AI models.
  • [CREDENTIALS_UNSAFE]:
  • Includes extensive dictionaries of known default credentials and administrative keys for a wide range of enterprise software, network equipment, and IoT devices.
Recommendations
  • CRITICAL: 5 infected file(s) detected - DO NOT USE
  • CRITICAL: 9 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 17, 2026, 09:27 AM
Security Audit — agent-trust-hub — pentest-tools