linux-pentester-commands
Fail
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill recommends downloading and executing unverified scripts from remote URLs using piped shell commands (curl | sh), which bypasses manual review of the executed code.
- [COMMAND_EXECUTION]: Multiple functional reverse shell templates are provided for Bash, Python, and Netcat, enabling unauthorized remote command execution on a target system.
- [COMMAND_EXECUTION]: Detailed persistence techniques are outlined, including unauthorized modification of system crontabs and SSH authorized_keys files to maintain long-term access.
- [COMMAND_EXECUTION]: The skill provides instructions for privilege escalation via SUID, Sudo, and PATH exploitation techniques to gain root-level access.
- [EXTERNAL_DOWNLOADS]: Includes instructions to clone external GitHub repositories and download automated enumeration tools from third-party sources without integrity checks.
- [DATA_EXFILTRATION]: Lists various methods for transferring files between systems using tools like curl, wget, and scp, which can be leveraged to exfiltrate sensitive data from a compromised host.
Recommendations
- HIGH: Downloads and executes remote code from: https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh - DO NOT USE without thorough review
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
Audit Metadata