goad
Fail
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill contains multiple hardcoded cleartext passwords for the
goadminaccount across different servers:8dCT-DJjgScp,NgtI75cKV+Pu,Ufe-bVXSx9rk, and978i2pF43UJ-. - [COMMAND_EXECUTION]: The documentation provides numerous shell commands for SSH connections, WinRM sessions, Ansible playbook execution, and security tools like
nmap,smbclient, andldapsearchdirected at specific IP addresses. - [REMOTE_CODE_EXECUTION]: The skill facilitates remote code execution by providing Python scripts that use the
winrmlibrary to execute commands on remote Windows servers, and SSH commands for the Ubuntu jumpbox. - [DATA_EXFILTRATION]: The skill explicitly references sensitive file paths for SSH private keys (
cyberagent/GOAD/workspace/03ea37-goad-aws/ssh_keys/ubuntu-jumpbox.pem), which represents a credential exposure risk.
Recommendations
- AI detected serious security threats
Audit Metadata