skills/aeondave/malskill/chisel/Gen Agent Trust Hub

chisel

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMPERSISTENCEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONOBFUSCATION
Full Analysis
  • [PERSISTENCE]: The skill provides instructions for establishing persistence on a Linux host by launching the Chisel client as a transient systemd unit using systemd-run --unit=pivot-chisel. This method ensures the tunnel remains active across shell deaths and cgroup terminations.
  • [PRIVILEGE_ESCALATION]: The persistence mechanism explicitly instructs the use of sudo systemd-run, requiring the agent or user to elevate privileges to root to maintain a persistent connection.
  • [COMMAND_EXECUTION]: The documentation focuses on executing commands on a "compromised host" to connect back to an "attacker" machine. These commands establish reverse SOCKS5 proxies and multiple port relays, facilitating remote control and internal network access.
  • [OBFUSCATION]: The skill details methods for evading detection, such as native TLS masking to bypass Deep Packet Inspection (DPI) and binary manipulation techniques like stripping symbols (-ldflags="-s -w") and UPX packing to evade Endpoint Detection and Response (EDR) systems.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — chisel