SSH Penetration Testing
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPERSISTENCEDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The skill explicitly instructs the agent on how to maintain access to a target system by adding a public key to the
~/.ssh/authorized_keysfile. - [CREDENTIALS_UNSAFE]: Instructions include searching for and reading sensitive private key files such as
~/.ssh/id_rsa,id_dsa,id_ecdsa, andid_ed25519, as well as host keys in/etc/ssh/. - [COMMAND_EXECUTION]: The skill relies on extensive use of powerful command-line tools for network scanning (
nmap), banner grabbing (nc,telnet), and automated credential attacks (hydra,medusa,ncrack). - [DATA_EXFILTRATION]: The instructions suggest using
curlandwgetto locate and download potentially exposed private keys and configuration backups from web-accessible directories on target servers. - [DYNAMIC_EXECUTION]: Provides a Python script template using the
paramikolibrary to dynamically automate SSH authentication and remote command execution. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill processes untrusted external data from tool outputs, including SSH banners, service versions, and network scan results.
- Boundary markers: None are defined to separate tool output from agent instructions.
- Capability inventory: The skill possesses high-privilege capabilities including full shell execution via SSH and Metasploit integration.
- Sanitization: There is no evidence of filtering or sanitizing external service data before it is ingested into the agent context.
Recommendations
- AI detected serious security threats
Audit Metadata