ssh-pentesting

Warn

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides explicit instructions to locate and extract sensitive cryptographic materials including private keys (~/.ssh/id_rsa, id_ed25519), authorized_keys, and known_hosts to facilitate lateral movement.
  • [DATA_EXFILTRATION]: Includes methods for session hijacking by identifying and accessing SSH agent socket files in /tmp, allowing the reuse of authenticated keys without knowing the passphrase.
  • [COMMAND_EXECUTION]: Instructs the agent to execute aggressive security auditing tools and network scanners including nmap, hydra, medusa, ncrack, and the Metasploit Framework.
  • [COMMAND_EXECUTION]: Documents the use of network-level attack tools such as arpspoof and ssh-mitm for intercepting SSH credentials through traffic redirection.
  • [CREDENTIALS_UNSAFE]: Contains a detailed table of default administrative credentials for a wide range of enterprise hardware vendors (Cisco, Citrix, Huawei, Juniper, etc.) to be used in automated brute-force attempts.
  • [EXTERNAL_DOWNLOADS]: References and encourages the use of specialized third-party exploit tools and credential datasets hosted on GitHub, such as SSH-Snake for automated lateral movement and SecLists for password dictionaries.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 12, 2026, 03:49 PM
Security Audit — agent-trust-hub — ssh-pentesting