ssh-key-scanner

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPERSISTENCEPRIVILEGE_ESCALATION
Full Analysis
  • [PERSISTENCE]: The skill provides explicit instructions and commands for maintaining unauthorized access to a system.
  • Includes commands to inject attacker-controlled public keys into the authorized_keys file for the root user and other accounts.
  • Describes techniques for stealth, such as modifying file timestamps (touch -t) to evade detection and hiding malicious logic in SSH environment variables.
  • [CREDENTIALS_UNSAFE]: Actively hunts for and attempts to read sensitive security material.
  • Targets private SSH keys (id_rsa, id_ed25519) and checks for non-standard or readable keys.
  • Scans SSH configuration files for hardcoded passwords and API keys.
  • Mentions resources (hacktricks.xyz) identified by security scanners as associated with offensive security tactics.
  • [COMMAND_EXECUTION]: Provides scripts for automated system-wide enumeration and network pivoting.
  • Features a multi-hop pivoting script that automatically attempts to use found keys to access discovered internal hosts.
  • Provides a full enumeration script to search all user home directories for SSH credentials.
  • [DATA_EXFILTRATION]: Facilitates the collection and external movement of harvested credentials.
  • Suggests the use of scp to transfer stolen private keys to an external machine.
  • Parses known_hosts and command histories to map out the network for further lateral movement.
  • [PRIVILEGE_ESCALATION]: Identifies methods for obtaining administrative control.
  • Directs the agent to access /etc/shadow to extract password hashes for cracking.
  • Scans for service account keys located in /opt or /var that may provide access to higher-privileged systems.
Recommendations
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — ssh-key-scanner