linux-persistence

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHPERSISTENCEPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONMETADATA_POISONING
Full Analysis
  • [PERSISTENCE]: The skill provides comprehensive instructions for establishing persistent access through several methods: adding SSH keys to authorized_keys files, creating recurring Cron jobs, setting up systemd services and timers, and modifying shell initialization files such as .bashrc and /etc/profile.d/.
  • [PRIVILEGE_ESCALATION]: Detailed commands are included to grant root access to specific service accounts without requiring a password by modifying the sudoers configuration.
  • [DYNAMIC_EXECUTION]: The skill provides C source code for creating malicious shared libraries used with LD_PRELOAD to hook system calls and spawn background backdoors. It also includes source code for a custom PAM module designed to harvest credentials during authentication.
  • [COMMAND_EXECUTION]: Snippets demonstrate the use of powerful system commands to install backdoors, fake file timestamps using touch, and suppress audit logs using auditctl to hide malicious activity from administrators.
  • [CREDENTIALS_UNSAFE]: The skill includes instructions and C code for credential harvesting, specifically capturing cleartext passwords during authentication events and logging them to a temporary file.
  • [DATA_EXFILTRATION]: It provides reverse shell patterns designed to be integrated into Cron jobs, facilitating periodic outbound network connections to an external attacker-controlled host.
  • [METADATA_POISONING]: The skill's description deceptively frames it as an audit and remediation resource, whereas the actual content focuses entirely on instructions for offensive exploitation and evasion.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — linux-persistence