linpeas
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONPERSISTENCEEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides a command to download and execute a shell script directly from GitHub via a pipe to bash in
SKILL.md(e.g.,curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | bash).- [PRIVILEGE_ESCALATION]: Thereferences/suid-capability-exploitation.mdfile contains detailed instructions and commands for exploiting SUID binaries, Linux capabilities, and sudo misconfigurations to gain administrative privileges.- [DATA_EXFILTRATION]: Documentation inreferences/suid-capability-exploitation.mdincludes templates for reverse shells using/dev/tcpto establish connections to external attacker-controlled IP addresses.- [CREDENTIALS_UNSAFE]: The skill provides instructions for harvesting credentials from user profile files (.bashrc, .zshrc), database configuration files, and accessing the sensitive/etc/shadowfile.- [COMMAND_EXECUTION]: Numerous examples are provided for spawning interactive root shells using various binaries like find, python, perl, and ruby.- [PERSISTENCE]: The skill details methods for maintaining access across system reboots, such as creating backdoor cron jobs and inserting SSH keys into the authorized_keys file.- [EXTERNAL_DOWNLOADS]: The skill references external URLs likebook.hacktricks.xyz, which have been flagged by security scanners for potential malicious associations.
Recommendations
- HIGH: Downloads and executes remote code from: https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh - DO NOT USE without thorough review
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata