# William2333ZZ

> Open-source publisher. Listings imported from github.com/William2333ZZ — credited to the original author with their license.

- **Listings:** 11
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/william2333zz
- **Website:** https://github.com/William2333ZZ

## Published listings

- [Rt1 Prompt Injection](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt1-prompt-injection) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt1-prompt-injection`
  Red-team an AI agent for prompt injection — does content the agent is asked to process (email, page, ticket, tool result) override its actual task? Authorized testing of agents you own or are permitted to test.
- [Rt4 Action Gating](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt4-action-gating) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt4-action-gating`
  Red-team an AI agent's high-risk action gating — can a costly or destructive action (pay, message, delete) reach execution without out-of-band human confirmation, especially under auto-approve/unattended modes? Authorized testing of agents you own or are permitted to test.
- [Rt7 Supply Chain](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt7-supply-chain) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt7-supply-chain`
  Red-team an AI agent's skill / plugin / MCP supply chain — can a poisoned skill doc, a malicious MCP server, or a dependency-confused package become persistent executable instruction? Authorized testing of agents you own or are permitted to test.
- [Rt5 Channel Injection](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt5-channel-injection) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt5-channel-injection`
  Red-team the channels an AI agent listens on (Telegram/Discord/Slack/WhatsApp/email/webhooks) — can untrusted inbound content, including group messages and forwards, steer the agent? Authorized testing of agents you own or are permitted to test.
- [Rt6 Memory Poisoning](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt6-memory-poisoning) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt6-memory-poisoning`
  Red-team an AI agent's persistent memory for cross-session prompt injection ("memory poisoning") — does untrusted content the agent processes get written into long-term memory and re-fire in future sessions with no attacker present? Authorized testing of agents you own or are permitted to test.
- [Rt2 Tool Abuse](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt2-tool-abuse) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt2-tool-abuse`
  Red-team an AI agent's tools — can it be coerced (often via injection) into calling a tool it shouldn't, with attacker-influenced arguments, or into acting as a confused deputy with its own privileges? Authorized testing of agents you own or are permitted to test.
- [Rt8 Data Exfiltration](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt8-data-exfiltration) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt8-data-exfiltration`
  Red-team an AI agent for data exfiltration — can an injection coax secrets, credentials, or sensitive data out of the agent through a tool call, a URL, or an outbound message? Authorized testing of agents you own or are permitted to test.
- [Rt3 Sandbox Escape](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt3-sandbox-escape) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt3-sandbox-escape`
  Red-team an AI agent's tool-execution isolation — do tools run un-sandboxed on the host, and does the sandbox silently disable itself when a dependency is missing? Authorized testing of agents you own or are permitted to test.
- [Crossval Harness](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-crossval-harness) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-crossval-harness`
  Orchestrate a static + dynamic, exploit-validated red-team of an AI agent — read the source to find candidate vulnerable paths, then run the dynamic skills to confirm or refute each one empirically. The arbiter of truth is whether the exploit works, not a model vote. Authorized testing of agents you own or are permitted to test.
- [Rt9 Multi Agent](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-rt9-multi-agent) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-rt9-multi-agent`
  Red-team a multi-agent system — can one agent (or content it relays) inject instructions into another, escalate privilege by hopping between agents, or turn an orchestrator/sub-agent handoff into a trust-laundering path? Authorized testing of systems you own or are permitted to test.
- [Redteam An Agent](https://agentstack.voostack.com/l/skill-william2333zz-trustshell-redteam-an-agent) — Skill · Free · security-reviewed — `agentstack add skill-william2333zz-trustshell-redteam-an-agent`
  The end-to-end methodology for red-teaming a specific AI agent — adaptively, exploit-validated, and honestly. Read THIS target's own code, stand up a disposable harness, and prove or refute each weakness through a real attacker-reachable entry point. This is the orchestration + discipline that makes a finding credible, not a list of payloads. Authorized testing of agents you own or are permitted…

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
