server-security-scan

Warn

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs sensitive file exposure by searching for and identifying authentication-related files, including SSH authorized keys (authorized_keys) and private keys (*.pem, id_rsa) across the file system.
  • [COMMAND_EXECUTION]: The skill executes a wide range of powerful system and security tools including nmap, ssh, nikto, nuclei, and lynis. It also performs deep system inspection using commands like sudo -l, find for SUID/SGID binaries, and searches through /etc/passwd and /etc/crontab.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to ipinfo.io to retrieve geolocation and ASN data for target IP addresses.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes untrusted data from server headers, service responses, and system log files via tools like nuclei, nikto, and nmap without explicit sanitization steps.
  • Ingestion points: Tool outputs from nmap, nikto, nuclei, and lynis; system files like /etc/os-release and crontab.
  • Boundary markers: None present in the instructions for tool output interpolation.
  • Capability inventory: Subprocess execution for all audit tools, SSH remote access, and local file reads across the filesystem.
  • Sanitization: No explicit sanitization or filtering of external tool output before report generation is documented.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 19, 2026, 09:44 AM
Security Audit — agent-trust-hub — server-security-scan