competition-linux-credential-pivot
Fail
Audited by Snyk on Jun 20, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). 该提示明确要求记录并展示 SSH 密钥、令牌、服务账号秘密、socket 与可重放链路等证据以证明“可重放”访问路径,这会强制模型包含或转述机密值的明文,从而构成凭证外泄风险。
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). 该技能明确指导收集与重放 Linux 凭证(SSH 密钥、agent sockets、kubeconfigs、云令牌、服务账号秘密等)以实现横向移动和特权提升,属于有意的凭证窃取、侧向渗透与系统侵害行为,风险极高。
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). 该技能明确要求查找、提取并重放 SSH 密钥、agent 套接字、kubeconfig、云令牌、sudoers/ setuid 等敏感工件并利用它们进行横向或纵向 pivot,实质上是在指示代理获取并滥用凭据以改变或滥用主机/网络的访问,属于高度会影响机器状态的恶意操作。
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata