ssh-key-scanner
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPERSISTENCEPRIVILEGE_ESCALATION
Full Analysis
- [PERSISTENCE]: The skill provides explicit instructions and commands for maintaining unauthorized access to a system.
- Includes commands to inject attacker-controlled public keys into the
authorized_keysfile for the root user and other accounts. - Describes techniques for stealth, such as modifying file timestamps (
touch -t) to evade detection and hiding malicious logic in SSH environment variables. - [CREDENTIALS_UNSAFE]: Actively hunts for and attempts to read sensitive security material.
- Targets private SSH keys (
id_rsa,id_ed25519) and checks for non-standard or readable keys. - Scans SSH configuration files for hardcoded passwords and API keys.
- Mentions resources (hacktricks.xyz) identified by security scanners as associated with offensive security tactics.
- [COMMAND_EXECUTION]: Provides scripts for automated system-wide enumeration and network pivoting.
- Features a multi-hop pivoting script that automatically attempts to use found keys to access discovered internal hosts.
- Provides a full enumeration script to search all user home directories for SSH credentials.
- [DATA_EXFILTRATION]: Facilitates the collection and external movement of harvested credentials.
- Suggests the use of
scpto transfer stolen private keys to an external machine. - Parses
known_hostsand command histories to map out the network for further lateral movement. - [PRIVILEGE_ESCALATION]: Identifies methods for obtaining administrative control.
- Directs the agent to access
/etc/shadowto extract password hashes for cracking. - Scans for service account keys located in
/optor/varthat may provide access to higher-privileged systems.
Recommendations
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata