ssh-penetration-testing
Fail
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell commands for network enumeration, brute-forcing, and post-exploitation using tools like Nmap, Hydra, and Medusa. It also includes instructions for establishing persistence by appending public keys to the
~/.ssh/authorized_keysfile. - [DATA_EXFILTRATION]: The skill guides the user to search for and access sensitive private keys (
id_rsa,id_dsa, etc.) in standard locations and within web-accessible directories, as well as extracting configuration and history files that may contain credentials. - [CREDENTIALS_UNSAFE]: The workflow involves automated credential attacks, including brute-forcing, password spraying using wordlists like
rockyou.txt, and searching shell history files (.bash_history) for hardcoded passwords.
Recommendations
- AI detected serious security threats
Audit Metadata