unauthorized-access-common-services
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEPROMPT_INJECTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides specific command sequences to exploit multiple services, including Redis, Rsync, and Hadoop YARN.
- [REMOTE_CODE_EXECUTION]: Detailed instructions for achieving remote code execution via FastCGI (PHP-FPM), AJP (Ghostcat), and YARN Resource Manager targeting external systems.
- [PRIVILEGE_ESCALATION]: Provides methods to write SSH public keys to the root user's directory and inject malicious cron jobs to execute commands with elevated privileges on target infrastructure.
- [PERSISTENCE]: Instructions for establishing persistent access by modifying crontabs and SSH authorized_keys files.
- [PROMPT_INJECTION]: The 'AI LOAD INSTRUCTION' encourages the model to adopt an 'Expert Attack Playbook' persona, which may override general safety constraints regarding the generation of offensive exploit code.
- [EXTERNAL_DOWNLOADS]: References multiple external exploitation tools (e.g.,
ajpShooter.py,redis-rogue-server.py,gopherus.py) and instructs the agent to utilize them for penetration testing tasks. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process output from scanning tools (like nmap) and execute complex exploitation logic based on that untrusted external data.
- Ingestion points: Service responses and scan results from
TARGEThosts during discovery phases. - Boundary markers: None present in the instructions to separate data from command logic.
- Capability inventory: Includes remote command execution, file system modification, and network requests via tools like
curlandredis-cli. - Sanitization: No sanitization or validation logic is defined for service responses before they are interpolated into exploitation commands.
Recommendations
- AI detected serious security threats
Audit Metadata