skills/aeondave/malskill/bore/Gen Agent Trust Hub

bore

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the bore binary from a third-party GitHub repository (https://github.com/ekzhang/bore/releases/latest/download/bore-v0.5.2-x86_64-unknown-linux-musl.tar.gz).
  • [REMOTE_CODE_EXECUTION]: Provides instructions to download, extract, and install an external binary to the system's execution path (/usr/local/bin), which results in the execution of code from an external source.
  • [COMMAND_EXECUTION]: Instructs the user to execute shell commands for tool installation and tunnel management, including curl, tar, cargo, and docker commands.
  • [PRIVILEGE_ESCALATION]: Includes commands that require elevated privileges, such as installing binaries to system directories, modifying firewall settings (ufw), and running network capture tools (sudo tcpdump).
  • [PERSISTENCE]: Supplies a systemd service configuration designed to ensure the tunneling server remains active across system restarts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — bore