skills/openhands/extensions/ssh/Gen Agent Trust Hub

ssh

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDATA_EXFILTRATIONPRIVILEGE_ESCALATIONPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides instructions for the agent to access and modify highly sensitive files within the ~/.ssh/ directory, including private keys, known hosts, and the SSH configuration file. While these actions are central to the skill's purpose, they represent a risk of exposing or modifying critical authentication data.
  • [PRIVILEGE_ESCALATION]: In the Windows documentation (references/windows.md), the skill suggests using Set-Service and Start-Service for the ssh-agent. These operations typically require administrative privileges on Windows, which could lead to an escalation of permissions if not properly managed.
  • [PERSISTENCE]: The skill includes instructions to configure the ssh-agent service with -StartupType Automatic on Windows systems. This creates a persistence mechanism where the service is automatically executed by the system during the boot process.
  • [DYNAMIC_EXECUTION]: The skill utilizes eval "$(ssh-agent -s)" to initialize the SSH agent in shell environments. Using eval on command output is a dynamic execution pattern that can be dangerous if the environment or the output of the subshell command is manipulated by an attacker.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill directly interpolates user-provided variables such as hostnames, usernames, ports, and aliases into shell commands across SKILL.md and README.md.
  • Boundary markers: There are no boundary markers or specialized instructions to delimit user input or prevent the agent from interpreting embedded shell characters as commands.
  • Capability inventory: The skill has extensive access to the system shell to execute ssh, scp, and ssh-keygen, as well as the ability to modify file permissions and system services.
  • Sanitization: The skill lacks instructions for validating or sanitizing user-provided connection strings, which could allow a malicious user to inject arbitrary shell commands or malicious SSH options (e.g., -oProxyCommand) through crafted hostnames or arguments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:34 AM
Security Audit — agent-trust-hub — ssh