sysadmin-toolbox
Fail
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/refresh.shscript performs agit clonefromhttps://github.com/trimstray/the-book-of-secret-knowledge.gitto populate and update the skill's reference files. This creates a dependency on an external, unverified source that can update the data processed by the agent.- [EXTERNAL_DOWNLOADS]: Automated scans identified the URLhttps://cybersecurity.wtfinreferences/security-tools.mdas malicious (blacklisted). While this is a known hacking challenge site, its presence in the reference data is flagged by reputation services.- [COMMAND_EXECUTION]: The skill provides reference material containing powerful and potentially dangerous shell commands. Examples include establishing a reverse shell (nc -l 5000 -e /bin/bash), terminating the current session (kill -9 $$), and deleting files based on age (find . -type f -mtime +60 -delete).- [PERSISTENCE]: The filereferences/shell-oneliners.mdincludes a command to modify/etc/profileby adding anEXITtrap. This modification affects system-wide login behavior and is a technique associated with persistence or unauthorized system changes.- [PRIVILEGE_ESCALATION]: The reference files provide links and descriptions for numerous local enumeration and privilege escalation tools (e.g., LinEnum, PEASS, SUDO_KILLER), which are used to find and exploit permissions vulnerabilities on a host.- [INDIRECT_PROMPT_INJECTION]: The skill has a large attack surface for indirect prompt injection because it automatically ingests data from external sources that contain executable shell patterns. If the ingested content contains malicious instructions, the agent could be manipulated into suggesting or executing them. - Ingestion points: All markdown files in the
references/directory. - Boundary markers: No delimiters or warnings to ignore instructions within the reference files are present.
- Capability inventory: The agent is explicitly equipped to handle shell commands, networking tasks, and system diagnostics.
- Sanitization: No sanitization or validation of the ingested markdown content is performed.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata