Back to skill

Security audit

Hexstrike

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent cybersecurity skill, but it gives broad direct-execution guidance for live scanning, exploitation, and credential attacks with insufficient scoping in the playbooks.

Install only if you intend to use it for owned, lab, CTF, or explicitly authorized security work. Before running any generated command, confirm the target scope, authorization, rate limits, and potential network or account impact, especially for full-port scans, vulnerability scanners, brute force tools, and credential-cracking workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (18)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
2. **Read** `references/ctf-playbook.md` for the matching category section

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
92% confidence
Finding

The skill includes a concrete example of running a full-port nmap service/script scan in the background against a target, which is active network reconnaissance and can be disruptive or unauthorized. In combination with direct exec support and broad offensive scope, this materially increases the risk of misuse, accidental scanning, or policy bypass through copy-pasteable commands.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

tion If critical tools are missing, suggest install commands:

  • Debian/Ubuntu: sudo apt install <package>
  • pip tools: pip3 install <package>
  • Go tools: go install <repo>@latest
  • Kali Linux: Most tools pre-installed; sudo apt install kali-tools-* for categories

Long-Running Scans

Use exec with background: true and yieldMs for scans that take minutes:

text
exec: nmap -sV -sC -p- <TARGET> -oA /tmp/full_scan
background: true, yieldMs: 30000

Check progress with process(action=poll).

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The directory traversal examples explicitly instruct users to retrieve sensitive system files such as /etc/passwd, which is a classic unauthorized file disclosure technique. In the context of an offensive-security skill, this is more dangerous because it is presented as a practical attack payload rather than abstract discussion.

Content

Scanner excerpt · references/ctf-playbook.md (reported line 48)May include surrounding context.

Filter bypass: , <svg/onload=alert(1)>

text

**Directory Traversal**: `../../../etc/passwd`, `....//....//etc/passwd`, `%2e%2e%2f`

**Authentication Bypass**: Default creds, JWT manipulation, cookie tampering, IDOR

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
91% confidence
Finding

The document includes direct credential-cracking workflows using john and hashcat with a common leaked-password wordlist, enabling password attacks against captured hashes. Because the surrounding skill is intended for offensive security use, these instructions lower the barrier to credential attacks and can facilitate unauthorized access.

Content

Scanner excerpt · references/ctf-playbook.md (reported line 78)May include surrounding context.

  • ROT13: echo "<TEXT>" | tr 'A-Za-z' 'N-ZA-Mn-za-m'
  • Caesar/shift: Try all 25 shifts
  • Vigenère: Frequency analysis → Kasiski examination → key length → solve
  • XOR: Known plaintext XOR ciphertext = key (repeating)
  • RSA weak keys: Small e with small m (cube root), common n (shared factor), Wiener's attack (large e), Fermat factoring (close p,q)

Cracking

bash
john --wordlist=/usr/share/wordlists/rockyou.txt --format=<FORMAT> <HASHFILE>
hashcat -m <MODE> -a 0 <HASHFILE> /usr/share/wordlists/rockyou.txt

Common hashcat modes: 0=MD5, 100=SHA1, 1400=SHA256, 1800=sha512crypt, 3200=bcrypt, 1000=NTLM

Pwn (Binary Exploitation)

Triage

bash
file <BINARY>
checksec --file <BINARY>
strings -n 8 <BINARY> | head -50
objdump -d -M intel <BINARY> | head -100
readelf -a <BINARY> | grep -E "RELRO|STACK|NX|PIE"

Checksec interpretation

  • No canary → Stack buffer overflow viable
  • NX disabled → Shellcode on stack
  • No PIE → Fix

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
95% confidence
Finding

The pwntools template provides a ready-made exploitation scaffold for connecting to a remote host and sending a crafted payload, which operationalizes binary exploitation rather than merely describing it. In a CTF-only document this could be educational, but the broader skill context explicitly includes pentesting and red-team tasks, making the capability more likely to be misused against real targets.

Content

Scanner excerpt · references/ctf-playbook.md (reported line 111)May include surrounding context.

RIP → shellcode or ret2win

  • ROP chain: ROPgadget --binary <BIN> or ropper --file <BIN> --search "pop rdi"
  • ret2libc: Leak libc address → calculate system/binsh offsets → call system("/bin/sh")
  • Format string: %p to leak stack, %n to write, %<offset>$p for specific positions
  • Heap: UAF, double-free, tcache poisoning, fastbin dup

Pwntools template

python
from pwn import *
context.binary = elf = ELF('./<binary>')
# p = process('./<binary>')  # Local
p = remote('<host>', <port>)  # Remote
# libc = ELF('./libc.so.6')

payload = b'A' * <OFFSET>
payload += p64(<ADDRESS>)
p.sendline(payload)
p.interactive()

Forensics

File Analysis

bash
file <FILE>
binwalk <FILE>  # Identify embedded files
binwalk -e <FILE>  # Extract embedded files
foremost -i <FILE> -o /tmp/output  # Carve files
exiftool <FILE>  # Metadata (GPS, author, timestamps, comments)
xxd <FILE> | head -20  # Hex dump — check magic bytes

Steganography

bash
stegh

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This methodology provides detailed active reconnaissance, vulnerability scanning, web exploitation, and credential-attack procedures without any gating, authorization requirements, safety warning, or impact guidance. In a skill explicitly marketed for offensive security and red-team use, this materially lowers the barrier to misuse against unauthorized targets and normalizes disruptive actions such as brute forcing, mass scanning, and exploit-oriented testing.

Content

No source excerpt is available for this finding.

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
94% confidence
Finding

The file contains numerous references to widely used offensive tools and ready-to-run commands, including sqlmap and hydra, alongside scanning and exploitation workflows. While tool names alone are not always harmful, here they appear in an operational pentest playbook that enables immediate offensive action, increasing the likelihood of unauthorized exploitation.

Content

Scanner excerpt · references/recon-methodology.md (reported line 48)May include surrounding context.

transparency curl -s "https://crt.sh/?q=%.&output=json" | jq -r '.[].name_value' | sort -u

Email harvesting

theHarvester -d -b all -l 500

text

## Phase 2: Active Reconnaissance

### Port Scanning
```bash
# Fast initial scan
rustscan -a <TARGET> --ulimit 5000 -- -sV -sC -oN rustscan.txt
# OR
masscan <TARGET> -p1-65535 --rate 1000 -oG masscan.txt

# Targeted follow-up with nmap
nmap -sV -sC -p <PORTS> -oA nmap_detailed <TARGET>

# Full comprehensive
nmap -sV -sC -A -T4 -p- -oA nmap_full <TARGET>

# UDP scan (top ports)
nmap -sU --top-ports 50 -sV <TARGET>

# Vulnerability scan
nmap --script vuln -p <PORTS> <TARGET>

Service-Specific Enumeration

HTTP/HTTPS (80, 443, 8080, 8443)

bash
httpx -u <TARGET> -probe -tech-detect -status-code -title -content-length -follow-redirects
whatweb -v -a 3 <URL>
wafw00f <URL>  # WAF detection
nuclei -u <URL> -severity critical,high -t cves/ -t exposures/ -t misconfiguration/

SMB (445)

bash
enum4linux-ng <TAR

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
97% confidence
Finding

The finding is triggered by explicit references to well-known offensive security tools, including tools for vulnerability scanning and password cracking. In isolation, naming tools is not inherently unsafe, but here the file supplies operational syntax for their immediate use, making the content practically actionable for offensive misuse.

Content

Scanner excerpt · references/tool-reference.md (reported line 9)May include surrounding context.

md
# Tool Quick Reference

Condensed syntax for 80+ security tools, organized by category.

## Network Scanning

| Tool | Quick Usage |
|------|------------|
| nmap | `nmap -sV -sC -p- -T4 <TARGET>` |
| rustscan | `rustscan -a <TARGET> --ulimit 5000 -- -sV -sC` |
| masscan | `masscan <TARGET> -p1-65535 --rate 1000` |
| autorecon | `autorecon <TARGET> -o /tmp/autorecon` |

## Subdomain & DNS

| Tool | Quick Usage |
|------|------------|
| amass | `amass enum -d <DOMAIN>` (active) / `-passive` |
| subfinder | `subfinder -d <DOMAIN> -silent` |
| fierce | `fierce --domain <DOMAIN>` |
| dnsenum | `dnsenum <DOMAIN>` |
| dnsrecon | `dnsrecon -d <DOMAIN> -t std,brt,axfr` |
| theHarvester | `theHarvester -d <DOMAIN> -b all -l 500` |

## Web Content Discovery

| Tool

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises direct execution of network-capable security tooling via exec but does not declare any explicit tool scope or permission boundary. In a high-risk offensive-security skill, missing least-privilege constraints increases the chance of unintended network access, unsafe command execution, or invocation in contexts where users did not intend live scanning behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list is extremely broad and includes common terms such as exploit, vulnerability, recon, and security audit, making accidental or unintended invocation likely. Because this skill is designed to run offensive and network-active tools directly, overbroad matching raises the risk that benign discussions are escalated into hazardous operational guidance or command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly promotes direct execution of 150+ security tools through exec and emphasizes no middleware or control layer, which reduces opportunities for policy enforcement, logging, and safety interlocks. In the context of pentesting, recon, brute force, and exploitation workflows, this creates a meaningful risk of system or network-impacting actions being launched too easily.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
### Tool Installation
If critical tools are missing, suggest install commands:
- **Debian/Ubuntu**: `sudo apt install <package>`
- **pip tools**: `pip3 install <package>`
- **Go tools**: `go install <repo>@latest`
- **Kali Linux**: Most tools pre-installed; `sudo apt install kali-tools-*` for categories

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
### Tool Installation
If critical tools are missing, suggest install commands:
- **Debian/Ubuntu**: `sudo apt install <package>`
- **pip tools**: `pip3 install <package>`
- **Go tools**: `go install <repo>@latest`
- **Kali Linux**: Most tools pre-installed; `sudo apt install kali-tools-*` for categories

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This playbook provides step-by-step offensive scanning, exploitation, credential cracking, and post-exploitation guidance with no authorization, scope, or safety framing. In a skill explicitly marketed for pentesting, red teaming, and offensive security, that omission materially increases the risk that users will be guided into unauthorized or harmful activity.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
89% confidence
Finding

The reconnaissance patterns include enumeration and scanning commands such as DNS recon, mass scanning, and service discovery. In isolation these can be legitimate for security assessment, but in this skill's offensive-security context and without any authorization safeguards, they facilitate broad target discovery and pre-attack mapping.

Content

Scanner excerpt · references/recon-methodology.md (reported line 24)May include surrounding context.

setfinder | sort -u > assetfinder.txt

Merge and deduplicate

cat amass_passive.txt subfinder.txt assetfinder.txt | sort -u > all_subs.txt

Historical URL discovery

cat all_subs.txt | waybackurls > wayback.txt cat all_subs.txt | gau > gau.txt cat wayback.txt gau.txt | sort -u | uro > all_urls.txt

DNS records

dig any +noall +answer dig axfr # Zone transfer attempt dnsrecon -d -t std,brt,axfr fierce --domain dnsenum

WHOIS

whois

Certificate transparency

curl -s "https://crt.sh/?q=%.&output=json" | jq -r '.[].name_value' | sort -u

Email harvesting

theHarvester -d -b all -l 500

text

## Phase 2: Active Reconnaissance

### Port Scanning
```bash
# Fast initial scan
rustscan -a <TARGET> --ulimit 5000 -- -sV -sC -oN rustscan.txt
# OR
masscan <TARGET> -p1-65535 --rate 1000 -oG masscan.txt

# Targeted follow-up with nmap
nmap -sV -sC -p <PORTS> -oA nmap_detailed <TARGET>

# Full comprehensive
nmap -sV -

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This reference file provides concise, ready-to-run commands for scanning, enumeration, and credential attacks without any authorization, safety, or rate-limiting guidance. In a skill explicitly designed for offensive security and red-team tasks, this materially lowers the barrier to misuse and can facilitate unauthorized reconnaissance or brute-force activity.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
95% confidence
Finding

This finding captures network reconnaissance and enumeration commands that can be used to map targets and identify attack surface. Because the skill’s stated purpose includes pentesting, recon, and offensive security, the presence of directly usable recon syntax increases the likelihood of unauthorized scanning if the skill is misapplied.

Content

Scanner excerpt · references/tool-reference.md (reported line 11)May include surrounding context.

md
# Tool Quick Reference

Condensed syntax for 80+ security tools, organized by category.

## Network Scanning

| Tool | Quick Usage |
|------|------------|
| nmap | `nmap -sV -sC -p- -T4 <TARGET>` |
| rustscan | `rustscan -a <TARGET> --ulimit 5000 -- -sV -sC` |
| masscan | `masscan <TARGET> -p1-65535 --rate 1000` |
| autorecon | `autorecon <TARGET> -o /tmp/autorecon` |

## Subdomain & DNS

| Tool | Quick Usage |
|------|------------|
| amass | `amass enum -d <DOMAIN>` (active) / `-passive` |
| subfinder | `subfinder -d <DOMAIN> -silent` |
| fierce | `fierce --domain <DOMAIN>` |
| dnsenum | `dnsenum <DOMAIN>` |
| dnsrecon | `dnsrecon -d <DOMAIN> -t std,brt,axfr` |
| theHarvester | `theHarvester -d <DOMAIN> -b all -l 500` |

## Web Content Discovery

| Tool | Quick Usage |
|------|------------|
| gobuster | `gobuster dir -u <URL> -w <WORDLIST> -x php,htm

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/tool-check.sh (reported line 33)May include surrounding context.

sh
ory="${1:-all}"
found=0; missing=0

check_tools() {
  local label="$1"; shift
  echo -e "\n${YELLOW}── $label ──${NC}"
  for tool in "$@"; do
    if check "$tool"; then ((found++)); else ((missing++)); fi
  done
}

if [[ "$category" == "all" || "$category" == "network" ]]; then
  check_tools "Network Scanning" nmap rustscan masscan autorecon
  check_tools "DNS & Subdomain" amass subfinder fierce dnsenum dnsrecon dig whois
  check_tools "SMB/Windows" enum4linux smbmap rpcclient nbtscan netexec evil-winrm
fi

if [[ "$category" == "all" || "$category" == "web" ]]; then
  check_tools "Web Discovery" gobuster feroxbuster ffuf dirsearch dirb
  check_tools "Web Scanning" nuclei nikto sqlmap dalfox wpscan wafw00f
  check_tools "Web Crawling" httpx katana whatweb
  check_tools "Parameters" arjun paramspider
fi

if [[ "$category" == "all" || "$category" == "crypto" ]]; then
  check_tools "Crypto/Cracking" hashcat john hash-identifier hashid openssl gpg
fi

if [[ "$category" == "all" || "

Static analysis

No suspicious patterns detected.