reverse-skill-router
Fail
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONOBFUSCATIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The file
field-journal/seed-012_log4shell-jndi-rce.mdcontains executable payloads for the Log4Shell vulnerability, including instructions on how to set up an LDAP server to deliver malicious Java classes. Automated scanners have confirmed this file as a malicious threat. - [DATA_EXFILTRATION]: The skill provides numerous templates and active commands for unauthorized data extraction.
field-journal/seed-017_xxe-oob-exfil.mdcontains payloads for out-of-band data exfiltration via XML External Entity attacks (flagged as malware). Files likefield-journal/anonymization.mdandfield-journal/precedent-pentest.mdinclude reverse shell one-liners used to establish unauthorized persistent outbound connections. - [PROMPT_INJECTION]: The
llm-securitymodule includes detailed methodologies for overriding LLM behavior. It provides specific payloads for 'DAN' role-play, system prompt extraction, and instructions to 'ignore all previous instructions' to bypass safety filters. - [OBFUSCATION]: The skill documentation uses Base64 encoding to conceal shell commands and payloads (e.g., in
field-journal/seed-012_log4shell-jndi-rce.md). It also describes the use of Unicode homoglyphs and zero-width characters as techniques to evade security scanners in AI interactions. - [DYNAMIC_EXECUTION]: The script
ida-reverse/scripts/run-supervisor.pymanipulates the Python import system to monkey-patch and dynamically alter the behavior of the IDA supervisor at runtime.diagram-generator/scripts/render_diagram.pyexecutes system processes based on input parameters derived from file extensions. - [EXTERNAL_DOWNLOADS]: The skill's bootstrap system (e.g.,
apk-reverse/scripts/decode.ps1) is configured to automatically download and install a broad range of third-party security and exploitation tools from remote GitHub repositories. - [COMMAND_EXECUTION]: Multiple scripts, such as
diagram-generator/scripts/render_diagram.py, use thesubprocess.runfunction to execute arbitrary shell commands.
Recommendations
- CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
Audit Metadata