SSH Penetration Testing
Fail
Audited by Snyk on Jul 28, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill hard-codes and prints plaintext credentials (e.g., example passwords in CLI commands and a Paramiko script that logs username:password), and shows adding an SSH key literal—patterns that require including secret values verbatim in outputs.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). These URLs expose web-accessible private SSH keys and a backup archive (sensitive credentials/exfiltrated data), which are highly suspicious as they can be used for unauthorized access or malware distribution.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This skill content provides explicit, actionable instructions for credential theft, brute-force attacks, remote code execution (reverse shells), persistence (adding authorized_keys), and covert tunneling suitable for unauthorized access and data exfiltration.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill contains explicit instructions to modify system files and persist access (e.g., echoing a SOCKS entry into /etc/proxychains.conf and appending an SSH key to authorized_keys), and it encourages checking/using sudo, which pushes the agent to change the host's state and may require elevated privileges.
Issues (4)
W007
HIGHInsecure credential handling detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata