pentest-tools

Fail

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: CRITICALPROMPT_INJECTIONDATA_EXFILTRATIONOBFUSCATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill contains playbooks and payload collections (e.g., in src-hunter/references/playbooks/llm-prompt-injection.md) that use prompt injection techniques, including 'ignore previous instructions', 'DAN' jailbreak mode, and system prompt extraction commands. These patterns pose a risk if the agent incorrectly interprets these test payloads as instructions for its own session.
  • [OBFUSCATION]: Multiple files contain Base64 encoded code snippets (e.g., in src-hunter/references/payloader/by-category/web/xss跨站脚本.md). Decoded content includes JavaScript for hijacking browsers and creating script tags pointing to external domains, as well as PHP code for executing system commands.
  • [REMOTE_CODE_EXECUTION]: The skill documentation includes instructions for downloading and executing scripts directly from the internet using curl | bash and IEX patterns (e.g., referring to installation scripts from untrusted GitHub repositories in references/pentest-ai-agents-matrix.md).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from untrusted targets (URLs, remote files, API responses) while possessing powerful capabilities to execute system commands and network operations. This creates a highly exploitable surface for indirect prompt injection where an external target could influence the agent's behavior.
  • [DATA_EXFILTRATION]: Payloads and instructions describe techniques for reading sensitive files (such as SSH keys, AWS credentials, and .env files) and exfiltrating the data to external 'Out-of-Band' servers or DNS logs.
  • [COMMAND_EXECUTION]: The skill integrates with various security tools and MCP servers to execute a wide range of system commands, including nmap, sqlmap, msfconsole, and various exploitation scripts.
  • [EXTERNAL_DOWNLOADS]: The skill documentation suggests downloading and installing numerous third-party tools, Docker images, and scripts from community-maintained repositories and registries.
  • [CREDENTIALS_UNSAFE]: The toolkit includes extensive dictionaries of default credentials for enterprise software, hardware appliances, and IoT devices.
  • [DYNAMIC_EXECUTION]: The skill provides methods for generating, loading, and executing code at runtime, primarily in the context of reverse shell payloads and vulnerability exploitation.
Recommendations
  • CRITICAL: 15 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 4, 2026, 01:52 AM
Security Audit — agent-trust-hub — pentest-tools