pentest-tools
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: CRITICALPROMPT_INJECTIONDATA_EXFILTRATIONOBFUSCATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill contains playbooks and payload collections (e.g., in
src-hunter/references/playbooks/llm-prompt-injection.md) that use prompt injection techniques, including 'ignore previous instructions', 'DAN' jailbreak mode, and system prompt extraction commands. These patterns pose a risk if the agent incorrectly interprets these test payloads as instructions for its own session. - [OBFUSCATION]: Multiple files contain Base64 encoded code snippets (e.g., in
src-hunter/references/payloader/by-category/web/xss跨站脚本.md). Decoded content includes JavaScript for hijacking browsers and creating script tags pointing to external domains, as well as PHP code for executing system commands. - [REMOTE_CODE_EXECUTION]: The skill documentation includes instructions for downloading and executing scripts directly from the internet using
curl | bashandIEXpatterns (e.g., referring to installation scripts from untrusted GitHub repositories inreferences/pentest-ai-agents-matrix.md). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from untrusted targets (URLs, remote files, API responses) while possessing powerful capabilities to execute system commands and network operations. This creates a highly exploitable surface for indirect prompt injection where an external target could influence the agent's behavior.
- [DATA_EXFILTRATION]: Payloads and instructions describe techniques for reading sensitive files (such as SSH keys, AWS credentials, and
.envfiles) and exfiltrating the data to external 'Out-of-Band' servers or DNS logs. - [COMMAND_EXECUTION]: The skill integrates with various security tools and MCP servers to execute a wide range of system commands, including
nmap,sqlmap,msfconsole, and various exploitation scripts. - [EXTERNAL_DOWNLOADS]: The skill documentation suggests downloading and installing numerous third-party tools, Docker images, and scripts from community-maintained repositories and registries.
- [CREDENTIALS_UNSAFE]: The toolkit includes extensive dictionaries of default credentials for enterprise software, hardware appliances, and IoT devices.
- [DYNAMIC_EXECUTION]: The skill provides methods for generating, loading, and executing code at runtime, primarily in the context of reverse shell payloads and vulnerability exploitation.
Recommendations
- CRITICAL: 15 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata