SSH Penetration Testing

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPERSISTENCEDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The skill explicitly instructs the agent on how to maintain access to a target system by adding a public key to the ~/.ssh/authorized_keys file.
  • [CREDENTIALS_UNSAFE]: Instructions include searching for and reading sensitive private key files such as ~/.ssh/id_rsa, id_dsa, id_ecdsa, and id_ed25519, as well as host keys in /etc/ssh/.
  • [COMMAND_EXECUTION]: The skill relies on extensive use of powerful command-line tools for network scanning (nmap), banner grabbing (nc, telnet), and automated credential attacks (hydra, medusa, ncrack).
  • [DATA_EXFILTRATION]: The instructions suggest using curl and wget to locate and download potentially exposed private keys and configuration backups from web-accessible directories on target servers.
  • [DYNAMIC_EXECUTION]: Provides a Python script template using the paramiko library to dynamically automate SSH authentication and remote command execution.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill processes untrusted external data from tool outputs, including SSH banners, service versions, and network scan results.
  • Boundary markers: None are defined to separate tool output from agent instructions.
  • Capability inventory: The skill possesses high-privilege capabilities including full shell execution via SSH and Metasploit integration.
  • Sanitization: There is no evidence of filtering or sanitizing external service data before it is ingested into the agent context.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — SSH Penetration Testing