linux-persistence
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHPERSISTENCEPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONMETADATA_POISONING
Full Analysis
- [PERSISTENCE]: The skill provides comprehensive instructions for establishing persistent access through several methods: adding SSH keys to authorized_keys files, creating recurring Cron jobs, setting up systemd services and timers, and modifying shell initialization files such as .bashrc and /etc/profile.d/.
- [PRIVILEGE_ESCALATION]: Detailed commands are included to grant root access to specific service accounts without requiring a password by modifying the sudoers configuration.
- [DYNAMIC_EXECUTION]: The skill provides C source code for creating malicious shared libraries used with LD_PRELOAD to hook system calls and spawn background backdoors. It also includes source code for a custom PAM module designed to harvest credentials during authentication.
- [COMMAND_EXECUTION]: Snippets demonstrate the use of powerful system commands to install backdoors, fake file timestamps using touch, and suppress audit logs using auditctl to hide malicious activity from administrators.
- [CREDENTIALS_UNSAFE]: The skill includes instructions and C code for credential harvesting, specifically capturing cleartext passwords during authentication events and logging them to a temporary file.
- [DATA_EXFILTRATION]: It provides reverse shell patterns designed to be integrated into Cron jobs, facilitating periodic outbound network connections to an external attacker-controlled host.
- [METADATA_POISONING]: The skill's description deceptively frames it as an audit and remediation resource, whereas the actual content focuses entirely on instructions for offensive exploitation and evasion.
Recommendations
- AI detected serious security threats
Audit Metadata