container-technique
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPERSISTENCE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides functional C source code in references/capability-escapes.md for a Linux Kernel Module (LKM) designed to initiate a reverse shell connection from the host operating system to an external IP.
- [PRIVILEGE_ESCALATION]: The instructions detail multiple high-severity techniques for breaking container isolation, including bind-mount abuse, capability exploitation (CAP_SYS_ADMIN, CAP_SYS_MODULE), and exploiting runtime vulnerabilities like CVE-2024-21626 to gain root access on the host.
- [COMMAND_EXECUTION]: The skill guides the agent to execute dangerous system commands that manipulate kernel-level features such as core_pattern and modprobe_path to run arbitrary scripts with host-level privileges.
- [CREDENTIALS_UNSAFE]: The documentation directs the agent to locate and exfiltrate sensitive credentials, including Kubernetes Service Account tokens, Docker TLS certificates, and the host's /etc/shadow file.
- [PERSISTENCE]: Detailed steps are provided for ensuring persistent access to the compromised host by modifying .ssh/authorized_keys, injecting malicious entries into crontabs, or creating new root-level users in /etc/passwd.
Recommendations
- AI detected serious security threats
Audit Metadata