reverse-skill-router

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONOBFUSCATIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The file field-journal/seed-012_log4shell-jndi-rce.md contains executable payloads for the Log4Shell vulnerability, including instructions on how to set up an LDAP server to deliver malicious Java classes. Automated scanners have confirmed this file as a malicious threat.
  • [DATA_EXFILTRATION]: The skill provides numerous templates and active commands for unauthorized data extraction. field-journal/seed-017_xxe-oob-exfil.md contains payloads for out-of-band data exfiltration via XML External Entity attacks (flagged as malware). Files like field-journal/anonymization.md and field-journal/precedent-pentest.md include reverse shell one-liners used to establish unauthorized persistent outbound connections.
  • [PROMPT_INJECTION]: The llm-security module includes detailed methodologies for overriding LLM behavior. It provides specific payloads for 'DAN' role-play, system prompt extraction, and instructions to 'ignore all previous instructions' to bypass safety filters.
  • [OBFUSCATION]: The skill documentation uses Base64 encoding to conceal shell commands and payloads (e.g., in field-journal/seed-012_log4shell-jndi-rce.md). It also describes the use of Unicode homoglyphs and zero-width characters as techniques to evade security scanners in AI interactions.
  • [DYNAMIC_EXECUTION]: The script ida-reverse/scripts/run-supervisor.py manipulates the Python import system to monkey-patch and dynamically alter the behavior of the IDA supervisor at runtime. diagram-generator/scripts/render_diagram.py executes system processes based on input parameters derived from file extensions.
  • [EXTERNAL_DOWNLOADS]: The skill's bootstrap system (e.g., apk-reverse/scripts/decode.ps1) is configured to automatically download and install a broad range of third-party security and exploitation tools from remote GitHub repositories.
  • [COMMAND_EXECUTION]: Multiple scripts, such as diagram-generator/scripts/render_diagram.py, use the subprocess.run function to execute arbitrary shell commands.
Recommendations
  • CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 05:45 AM
Security Audit — agent-trust-hub — reverse-skill-router