linux-file-path-abuse
Fail
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: An automated AV scanner identified the skill file as infected with the Python:Agent-AKS Trojan.\n- [COMMAND_EXECUTION]: The skill automates privilege escalation through Docker and LXD containers by mounting the host filesystem to modify root-owned system configuration files.\n- [COMMAND_EXECUTION]: The skill provides automated commands to modify /etc/passwd, /etc/shadow, and /etc/sudoers for the purpose of creating unauthorized root users and persistent system backdoors.\n- [DATA_EXFILTRATION]: The skill facilitates the unauthorized reading and extraction of sensitive system data, including password hashes from /etc/shadow and root SSH private keys, using raw block device access via debugfs.\n- [REMOTE_CODE_EXECUTION]: Techniques for shared library hijacking and PATH hijacking are included to execute arbitrary code with elevated system privileges.\n- [REMOTE_CODE_EXECUTION]: Static analysis detected reverse shell patterns and destructive system command patterns within the instruction set.\n- [REMOTE_CODE_EXECUTION]: The skill establishes persistence by injecting malicious payloads into system-wide and user-level profile scripts such as .bashrc and /etc/profile.d/.\n- [PROMPT_INJECTION]: The skill ingests external data from an engagement state MCP server and interpolates it into prompts without sanitization, creating a vulnerability to indirect prompt injection.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
Audit Metadata