container-escape-techniques
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill contains exhaustive documentation and command sequences designed to bypass container isolation and gain host-level root privileges. It details methods for mounting host devices, entering host namespaces using
nsenter, and exploiting Linux capabilities such asCAP_SYS_ADMINandCAP_DAC_READ_SEARCH. - [COMMAND_EXECUTION]: The instructions include numerous high-risk shell commands for system manipulation, including exploiting
cgroup v1release agents to execute arbitrary commands on the host and usinggdbor Python for process injection. - [PERSISTENCE]: The
DOCKER_ESCAPE_CHAINS.mdfile provides explicit instructions for maintaining access to the host after a successful breakout. This includes adding an attacker's public key to the host's/root/.ssh/authorized_keysand setting up a recurring reverse shell backdoor in/etc/crontab. - [DATA_EXFILTRATION]: The playbook specifically targets sensitive system files, providing commands to read the host's
/etc/shadowfile, which contains encrypted password hashes for all system users. - [CREDENTIALS_UNSAFE]: The skill promotes the unauthorized modification of authentication files (
authorized_keys) to bypass standard login procedures and facilitate remote access for an attacker.
Recommendations
- AI detected serious security threats
Audit Metadata