T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:3- Finding
Audit Commands Are Executed Through an Unrestricted Root SSH Session
- Content
View full analysis
'<команда>'` --- ## Крок 0 — Визначення типу сервера ``` exec: ssh root@HOST 'pveversion 2>/dev/null && echo TYPE=PROXMOX || echo TYPE=LINUX' ``` ``` The same root SSH execution pattern is subsequently used for all audit commands in `SKILL.md`. ### Technical Analysis The Skill mandates direct SSH authentication as `root` for the complete audit. Some hardware and kernel diagnostics may require elevated permissions, but many commands in the workflow—such as `free`, `lsblk`, `ip`, `ss`, `ps`, `uptime`, and portions of `systemctl` inspection—do not require unrestricted root access. This design violates the principle of least privilege. The statement that the audit is read-only is only an instruction-level restriction; it is not enforced by SSH authorization, shell restrictions, command allowlisting, mandatory access controls, or a constrained privilege boundary. Once the root SSH session is established, the execution channel technically has permission to read, modify, or delete any data accessible to the host's root account. The risk is amplified by the use of command templates containing replaceable host, disk, and interface identifiers. Any future command-generation error, unsafe extension, malicious modification of the Skill, or shell metacharacter introduced into a dynamically composed command would execute with complete system privileges. ### Attack Path 1. A user requests an audit of a Linux or Proxmox server. 2. The agent follows the required template and authenticates directly as `root`. 3. The Skill opens a remote shell execution channel without a server-side command allowlist. 4. Commands are gene ...[truncated 1116 chars]- Remediation
View remediation
