Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs the operator to establish persistence by appending an SSH key to authorized_keys after access is gained. That goes beyond assessment or auditing and enables continued unauthorized access, which materially increases harm and changes the activity from testing to post-compromise persistence.
