src-hunter
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: CRITICALPROMPT_INJECTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEOBFUSCATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides comprehensive guides on bypassing LLM safety filters, using jailbreak characters, and extracting system prompts. Evidence found in 'references/playbooks/llm-prompt-injection.md' and 'references/payloader/by-category/web/ai安全.md' includes techniques like 'Ignore all previous instructions' and role-playing scenarios (e.g., DAN mode).
- [DATA_EXFILTRATION]: Payload libraries contain numerous examples for exfiltrating data via DNS, HTTP (curl/wget), and ICMP. Files like 'references/playbooks/rce.md' and 'references/payloader/by-category/web/ssrf服务端请求伪造.md' demonstrate how to send system files (/etc/passwd) and cloud metadata to attacker-controlled servers.
- [CREDENTIALS_UNSAFE]: The skill documents methods for harvesting high-value secrets, including SSH private keys, AWS/GCP/Azure IAM credentials, and database passwords. Dictionaries like 'references/dictionaries/default-credentials-cn.md' contain default passwords for enterprise software and IoT devices.
- [OBFUSCATION]: Extensive use of Base64, Hex, and Unicode homoglyphs is documented as a primary method for bypassing Web Application Firewalls (WAF). Static detectors identified obfuscated execution chains in 'references/payloader/waf-bypass.md' and 'references/payloader/by-category/web/xss跨站脚本.md'.
- [EXTERNAL_DOWNLOADS]: The skill references and provides commands to install various third-party security tools from untrusted GitHub repositories and package registries. It specifically integrates with 'jshookmcp', a powerful MCP server from an unverified source.
- [REMOTE_CODE_EXECUTION]: Multiple playbooks (e.g., 'references/playbooks/rce.md' and 'references/playbooks/file-upload.md') provide ready-to-use reverse shell commands and webshell code for gaining full control of remote servers.
- [COMMAND_EXECUTION]: The skill encourages the use of dangerous system commands (e.g., 'id', 'whoami', 'cat /etc/shadow') for reconnaissance and verification of exploit success.
- [PRIVILEGE_ESCALATION]: Dedicated playbooks describe techniques for escalating privileges on Windows (via Potato-style exploits), Linux (via SUID/sudo), and Active Directory environments.
- [PERSISTENCE]: The toolkit includes instructions for maintaining long-term access to compromised systems using registry Run keys, systemd services, and SSH authorized_keys (found in 'references/playbooks/intranet-postexp.md').
- [INDIRECT_PROMPT_INJECTION]: The skill has a high vulnerability surface for indirect prompt injection. It is designed to ingest untrusted data from targets (Recon/Hunt phases) and has access to high-capability tools (browser, network, ADB bridge).
- Ingestion points: Target discovery phase in 'Phase 1' and 'Phase 2' of the workflow.
- Boundary markers: Absent for processed external data; no explicit warnings to ignore instructions found within target content.
- Capability inventory: Full network access, browser automation, and process management via jshookmcp.
- Sanitization: No mention of sanitizing target responses before processing via the LLM.
Recommendations
- CRITICAL: 9 infected file(s) detected - DO NOT USE
- CRITICAL: 14 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata