bore
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the
borebinary from a third-party GitHub repository (https://github.com/ekzhang/bore/releases/latest/download/bore-v0.5.2-x86_64-unknown-linux-musl.tar.gz). - [REMOTE_CODE_EXECUTION]: Provides instructions to download, extract, and install an external binary to the system's execution path (
/usr/local/bin), which results in the execution of code from an external source. - [COMMAND_EXECUTION]: Instructs the user to execute shell commands for tool installation and tunnel management, including
curl,tar,cargo, anddockercommands. - [PRIVILEGE_ESCALATION]: Includes commands that require elevated privileges, such as installing binaries to system directories, modifying firewall settings (
ufw), and running network capture tools (sudo tcpdump). - [PERSISTENCE]: Supplies a systemd service configuration designed to ensure the tunneling server remains active across system restarts.
Audit Metadata