sysadmin-toolbox

Fail

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/refresh.sh script performs a git clone from https://github.com/trimstray/the-book-of-secret-knowledge.git to populate and update the skill's reference files. This creates a dependency on an external, unverified source that can update the data processed by the agent.- [EXTERNAL_DOWNLOADS]: Automated scans identified the URL https://cybersecurity.wtf in references/security-tools.md as malicious (blacklisted). While this is a known hacking challenge site, its presence in the reference data is flagged by reputation services.- [COMMAND_EXECUTION]: The skill provides reference material containing powerful and potentially dangerous shell commands. Examples include establishing a reverse shell (nc -l 5000 -e /bin/bash), terminating the current session (kill -9 $$), and deleting files based on age (find . -type f -mtime +60 -delete).- [PERSISTENCE]: The file references/shell-oneliners.md includes a command to modify /etc/profile by adding an EXIT trap. This modification affects system-wide login behavior and is a technique associated with persistence or unauthorized system changes.- [PRIVILEGE_ESCALATION]: The reference files provide links and descriptions for numerous local enumeration and privilege escalation tools (e.g., LinEnum, PEASS, SUDO_KILLER), which are used to find and exploit permissions vulnerabilities on a host.- [INDIRECT_PROMPT_INJECTION]: The skill has a large attack surface for indirect prompt injection because it automatically ingests data from external sources that contain executable shell patterns. If the ingested content contains malicious instructions, the agent could be manipulated into suggesting or executing them.
  • Ingestion points: All markdown files in the references/ directory.
  • Boundary markers: No delimiters or warnings to ignore instructions within the reference files are present.
  • Capability inventory: The agent is explicitly equipped to handle shell commands, networking tasks, and system diagnostics.
  • Sanitization: No sanitization or validation of the ingested markdown content is performed.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 19, 2026, 05:41 PM
Security Audit — agent-trust-hub — sysadmin-toolbox