skills/aeondave/malskill/misc-ctf/Gen Agent Trust Hub

misc-ctf

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPERSISTENCEDATA_EXFILTRATIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill provides extensive methodologies for gaining unauthorized privileges, including:
  • Exploiting sudo wildcard parameter injection via fnmatch to bypass argument restrictions.
  • Utilizing polkit integer overflows (CVE-2018-19788) to execute commands as root.
  • Abusing SUID binaries and capabilities on Linux systems, including using PostgreSQL to create root-owned SUID shells.
  • Escalating privileges within containers using privileged mounts, capability abuse, and exploiting BuildKit daemons.
  • [COMMAND_EXECUTION]: Instructions describe how to spawn interactive shells from highly restricted environments:
  • Spawning a bash shell using the \$$# expansion in restricted shells.
  • Using Python decorator chains to invoke os.system when ast.Call nodes are blocked.
  • Escaping rvim (restricted vim) jails via the K (man) command, netrw file browser, or Python3 script execution.
  • [REMOTE_CODE_EXECUTION]: The skill includes patterns for executing code from remote or untrusted sources:
  • Piping curl or wget output directly into shell interpreters (curl|bash).
  • Injecting malicious payloads via Python's marshal serialization and code object deserialization.
  • Exploiting exposed BuildKit daemons via gRPC to submit nested build requests that read host secrets.
  • [PERSISTENCE]: The documentation includes techniques for maintaining access across sessions, specifically by appending malicious commands to shell profiles such as ~/.bashrc.
  • [DATA_EXFILTRATION]: Provides methods for identifying and exfiltrating sensitive data from the environment:
  • Scanning /proc/*/cmdline to discover and connect to internal services serving sensitive data.
  • Using /dev/tcp built-ins for exfiltration when standard networking tools are missing.
  • Implementing DNS tunneling and exfiltration via subdomains and TXT records.
  • [DYNAMIC_EXECUTION]: Extensively uses dynamic code execution primitives for exploitation:
  • Using eval() and exec() calls in multiple Python jailbreak contexts.
  • Deserialization of untrusted code objects via marshal.loads().
  • Exploiting Turing-complete template languages like XSLT to build computational oracles.
  • [CREDENTIALS_UNSAFE]: Documents the harvesting and decryption of sensitive credentials:
  • Explicit instructions for accessing ~/.aws/credentials, ~/.ssh/id_rsa, and .env files.
  • Extracting password hashes from PostgreSQL pg_authid files for offline cracking.
  • Decrypting stored SSH credentials from desktop clients like WinSSHTerm by reversing PBKDF2-based encryption schemes.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection:
  • Ingestion points: Interacts with external CTFd platforms via API to download challenge descriptions and files.
  • Boundary markers: None identified; instructions do not warn the agent to ignore instructions embedded in the challenge data.
  • Capability inventory: Full subprocess control, network operations, file writing, and credential handling.
  • Sanitization: No evidence of sanitization for data retrieved from external platforms before processing.
  • [EXTERNAL_DOWNLOADS]: Includes patterns for downloading external scripts and binaries (e.g., hook.so, buildctl) from remote servers for use in exploitation.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — misc-ctf