skills/drolu/agent-skills/goad/Gen Agent Trust Hub

goad

Fail

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill contains multiple hardcoded cleartext passwords for the goadmin account across different servers: 8dCT-DJjgScp, NgtI75cKV+Pu, Ufe-bVXSx9rk, and 978i2pF43UJ-.
  • [COMMAND_EXECUTION]: The documentation provides numerous shell commands for SSH connections, WinRM sessions, Ansible playbook execution, and security tools like nmap, smbclient, and ldapsearch directed at specific IP addresses.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates remote code execution by providing Python scripts that use the winrm library to execute commands on remote Windows servers, and SSH commands for the Ubuntu jumpbox.
  • [DATA_EXFILTRATION]: The skill explicitly references sensitive file paths for SSH private keys (cyberagent/GOAD/workspace/03ea37-goad-aws/ssh_keys/ubuntu-jumpbox.pem), which represents a credential exposure risk.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 2, 2026, 07:10 PM
Security Audit — agent-trust-hub — goad