{"data":{"skill":{"slug":"sickn33-network-101","name":"network-101","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/network-101","status":"approved","author":"zebbern","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"302c6a70-9f0b-401d-8518-576d04b61bb7","skill_id":"bc118fa9-1f0d-4156-9665-c965d9300324","version":6,"content_hash":"v3:81e05e636292629114b76cbb3922fbe57672fc02:64e8a0f23fad3c68c9b5f27115ed725dd61bbbcd281bfd3cdde4b590d853547d:4139395cdade48472604f76a5fdb40ea823296abf449f41c8cbafee62f925012:736b696c6c732f7369636b6e33332f6e6574776f726b2d313031:4b5ede5919c411d5d8ba7f3aede5bae5","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"The skill is an authorized network-lab guide, and many alerts are false positives caused by Markdown fences, documentation labels, and private example addresses. Privileged host changes, service persistence, active network enumeration, and binding to all interfaces are confirmed risks. Weak SNMP, anonymous writable SMB, and credential-form examples require stronger isolation and handling guidance.","remediation":[{"issue":"Commands install packages, alter firewalls, modify service files, and enable startup behavior with root privileges.","severity":"high","suggestion":"Require confirmation immediately before each privileged block, name the affected host, and provide rollback commands for every persistent change."},{"issue":"SNMP examples use cleartext v1 communities and predictable public or private values.","severity":"high","suggestion":"Default to SNMPv3 with unique credentials. Keep legacy examples bound to an isolated interface and state that they must never reach production networks."},{"issue":"The Samba example permits guest access and marks the share writable.","severity":"high","suggestion":"Use read-only guest access by default, require named test accounts for writes, and include commands that remove the share after testing."},{"issue":"Enumeration commands can scan the wrong target or exceed an assessment scope.","severity":"high","suggestion":"Require an explicit target substitution, approved ports, rate limits, and a final scope confirmation before any scan runs."},{"issue":"The sample login form can collect credentials without defining safe handling.","severity":"medium","suggestion":"Use synthetic credentials only, enable HTTPS, avoid persistence, and document immediate deletion of request logs and submitted values."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":73,"line_start":60},{"file":"SKILL.md","line_end":77,"line_start":73},{"file":"SKILL.md","line_end":83,"line_start":77},{"file":"SKILL.md","line_end":91,"line_start":83},{"file":"SKILL.md","line_end":100,"line_start":91},{"file":"SKILL.md","line_end":104,"line_start":100},{"file":"SKILL.md","line_end":111,"line_start":104},{"file":"SKILL.md","line_end":115,"line_start":111},{"file":"SKILL.md","line_end":124,"line_start":115},{"file":"SKILL.md","line_end":132,"line_start":124},{"file":"SKILL.md","line_end":145,"line_start":132},{"file":"SKILL.md","line_end":154,"line_start":145},{"file":"SKILL.md","line_end":169,"line_start":154},{"file":"SKILL.md","line_end":183,"line_start":169},{"file":"SKILL.md","line_end":202,"line_start":183},{"file":"SKILL.md","line_end":206,"line_start":202},{"file":"SKILL.md","line_end":221,"line_start":206},{"file":"SKILL.md","line_end":229,"line_start":221},{"file":"SKILL.md","line_end":238,"line_start":229},{"file":"SKILL.md","line_end":242,"line_start":238},{"file":"SKILL.md","line_end":248,"line_start":242},{"file":"SKILL.md","line_end":264,"line_start":248},{"file":"SKILL.md","line_end":276,"line_start":264},{"file":"SKILL.md","line_end":301,"line_start":276},{"file":"SKILL.md","line_end":321,"line_start":301},{"file":"SKILL.md","line_end":325,"line_start":321},{"file":"SKILL.md","line_end":333,"line_start":325},{"file":"SKILL.md","line_end":337,"line_start":333},{"file":"SKILL.md","line_end":345,"line_start":337},{"file":"SKILL.md","line_end":352,"line_start":345},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":93,"line_start":93},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":110,"line_start":110},{"file":"SKILL.md","line_end":134,"line_start":134},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":144,"line_start":144},{"file":"SKILL.md","line_end":185,"line_start":185},{"file":"SKILL.md","line_end":188,"line_start":188},{"file":"SKILL.md","line_end":191,"line_start":191},{"file":"SKILL.md","line_end":201,"line_start":201},{"file":"SKILL.md","line_end":231,"line_start":231}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":123,"line_start":123},{"file":"SKILL.md","line_end":266,"line_start":266},{"file":"SKILL.md","line_end":269,"line_start":269},{"file":"SKILL.md","line_end":117,"line_start":117},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":123,"line_start":123},{"file":"SKILL.md","line_end":156,"line_start":156},{"file":"SKILL.md","line_end":159,"line_start":159},{"file":"SKILL.md","line_end":162,"line_start":162},{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":168,"line_start":168},{"file":"SKILL.md","line_end":208,"line_start":208},{"file":"SKILL.md","line_end":211,"line_start":211},{"file":"SKILL.md","line_end":214,"line_start":214},{"file":"SKILL.md","line_end":217,"line_start":217},{"file":"SKILL.md","line_end":220,"line_start":220},{"file":"SKILL.md","line_end":356,"line_start":356}]}],"critical_findings":[],"high_findings":[{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":62,"line_start":62}],"confidence":0.97,"description":"sudo apt update && sudo apt install apache2","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command installs or updates system packages with root privileges on line 62. It changes the host and requires explicit operator approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":65,"line_start":65}],"confidence":0.97,"description":"sudo systemctl start apache2","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes a system service on line 65, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":66,"line_start":66}],"confidence":0.97,"description":"sudo systemctl enable apache2","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes a system service on line 66, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":69,"line_start":69}],"confidence":0.97,"description":"echo \"<html><body><h1>Test Page</h1></body></html>\" | sudo tee /var/www/html/index.html","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command writes content into a root-owned system or service path on line 69. It makes a privileged host change that requires explicit approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":79,"line_start":79}],"confidence":0.97,"description":"sudo ufw allow 80/tcp","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes the host firewall on line 79 and exposes an inbound service. An incorrect target or environment could expand network access."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":93,"line_start":93}],"confidence":0.97,"description":"sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 \\","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command creates a private key and certificate in system directories on line 93. It writes security-sensitive host configuration and needs operator approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":98,"line_start":98}],"confidence":0.97,"description":"sudo a2enmod ssl","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command writes content into a root-owned system or service path on line 98. It makes a privileged host change that requires explicit approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":99,"line_start":99}],"confidence":0.97,"description":"sudo systemctl restart apache2","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes a system service on line 99, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":106,"line_start":106}],"confidence":0.97,"description":"sudo nano /etc/apache2/sites-available/default-ssl.conf","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command opens a root-owned service configuration file for modification on line 106. Incorrect edits can weaken or disrupt the host service."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":109,"line_start":109}],"confidence":0.97,"description":"sudo a2ensite default-ssl","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command writes content into a root-owned system or service path on line 109. It makes a privileged host change that requires explicit approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":110,"line_start":110}],"confidence":0.97,"description":"sudo systemctl reload apache2","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes a system service on line 110, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":134,"line_start":134}],"confidence":0.97,"description":"sudo apt install snmpd snmp","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command installs or updates system packages with root privileges on line 134. It changes the host and requires explicit operator approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":137,"line_start":137}],"confidence":0.97,"description":"sudo nano /etc/snmp/snmpd.conf","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command opens a root-owned service configuration file for modification on line 137. Incorrect edits can weaken or disrupt the host service."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":144,"line_start":144}],"confidence":0.97,"description":"sudo systemctl restart snmpd","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes a system service on line 144, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":185,"line_start":185}],"confidence":0.97,"description":"sudo apt install samba","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command installs or updates system packages with root privileges on line 185. It changes the host and requires explicit operator approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":188,"line_start":188}],"confidence":0.97,"description":"sudo install -d -m 0770 -o root -g sambashare /srv/samba/share","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command creates a service directory and assigns permissions on line 188. It changes filesystem ownership and access controls on the host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":191,"line_start":191}],"confidence":0.97,"description":"sudo nano /etc/samba/smb.conf","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command opens a root-owned service configuration file for modification on line 191. Incorrect edits can weaken or disrupt the host service."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":201,"line_start":201}],"confidence":0.97,"description":"sudo systemctl restart smbd","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes a system service on line 201, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":231,"line_start":231}],"confidence":0.97,"description":"sudo tail -f /var/log/apache2/access.log","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command reads service logs with root privileges on line 231. Logs can contain sensitive request data and should only be accessed on authorized systems."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":234,"line_start":234}],"confidence":0.97,"description":"sudo tail -f /var/log/apache2/error.log","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command reads service logs with root privileges on line 234. Logs can contain sensitive request data and should only be accessed on authorized systems."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":303,"line_start":303}],"confidence":0.97,"description":"sudo apt install apache2","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command installs or updates system packages with root privileges on line 303. It changes the host and requires explicit operator approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":304,"line_start":304}],"confidence":0.97,"description":"sudo systemctl start apache2","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes a system service on line 304, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":307,"line_start":307}],"confidence":0.97,"description":"cat << 'EOF' | sudo tee /var/www/html/login.html","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command writes content into a root-owned system or service path on line 307. It makes a privileged host change that requires explicit approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":320,"line_start":320}],"confidence":0.97,"description":"sudo ufw allow 80/tcp","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes the host firewall on line 320 and exposes an inbound service. An incorrect target or environment could expand network access."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":327,"line_start":327}],"confidence":0.97,"description":"sudo apt install snmpd","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command installs or updates system packages with root privileges on line 327. It changes the host and requires explicit operator approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":328,"line_start":328}],"confidence":0.97,"description":"echo \"rocommunity public\" | sudo tee -a /etc/snmp/snmpd.conf","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command writes content into a root-owned system or service path on line 328. It makes a privileged host change that requires explicit approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":329,"line_start":329}],"confidence":0.97,"description":"sudo systemctl restart snmpd","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command changes a system service on line 329, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":339,"line_start":339}],"confidence":0.97,"description":"sudo apt install samba","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command installs or updates system packages with root privileges on line 339. It changes the host and requires explicit operator approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":341,"line_start":341}],"confidence":0.97,"description":"sudo install -d -m 0770 -o root -g sambashare /srv/samba/anonymous","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This root command creates a service directory and assigns permissions on line 341. It changes filesystem ownership and access controls on the host."},{"title":"Systemd service enablement","locations":[{"file":"SKILL.md","line_end":66,"line_start":66}],"confidence":0.98,"description":"sudo systemctl enable apache2","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The command enables Apache to start automatically at boot. This is a persistent system change, even though the stated purpose is legitimate lab setup."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":117,"line_start":117}],"confidence":0.98,"description":"nmap -p 443 192.168.1.1","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":217,"line_start":217}],"confidence":0.98,"description":"enum4linux -a 192.168.1.1","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":220,"line_start":220}],"confidence":0.98,"description":"nmap --script smb-vuln* 192.168.1.1","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail."},{"title":"Insecure SNMP Lab Configuration","locations":[{"file":"SKILL.md","line_end":144,"line_start":139},{"file":"SKILL.md","line_end":168,"line_start":156},{"file":"SKILL.md","line_end":332,"line_start":327}],"confidence":0.98,"description":"The guide recommends SNMP v1 with public and private community strings, then demonstrates process enumeration and community-string guessing. Exposure outside an isolated lab could disclose system details.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The commands and configuration explicitly use cleartext SNMP v1 and the well-known public community. The skill also acknowledges this protocol limitation."},{"title":"Anonymous Writable SMB Configuration","locations":[{"file":"SKILL.md","line_end":201,"line_start":193}],"confidence":0.91,"description":"The sample share enables guest access and disables read-only mode. A reachable lab host could accept unauthorized file changes if the filesystem permissions also permit them.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The Samba configuration explicitly sets guest access to yes and read-only to no. Actual write access still depends on the shown directory permissions and Samba identity mapping."}],"medium_findings":[{"title":"Hardcoded IP address","locations":[{"file":"SKILL.md","line_end":356,"line_start":356}],"confidence":0.96,"description":"| Cannot connect remotely | Bind service to 0.0.0.0 instead of localhost |","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The troubleshooting advice recommends binding a service to 0.0.0.0. This exposes it on every interface and can unintentionally make a weak lab service reachable."},{"title":"Credential Collection Page Without Handling Guidance","locations":[{"file":"SKILL.md","line_end":317,"line_start":307}],"confidence":0.9,"description":"The HTTP example creates a login form that requests a username and password. It omits guidance on test credentials, storage, transport, and cleanup.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The example visibly requests password input and posts it to login.php. No backend or exfiltration is shown, but unsafe lab handling could expose entered credentials."}],"low_findings":[],"dangerous_patterns":[{"title":"Systemd service enablement","locations":[{"file":"SKILL.md","line_end":66,"line_start":66}],"confidence":0.98,"description":"sudo systemctl enable apache2","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The command enables Apache to start automatically at boot. This is a persistent system change, even though the stated purpose is legitimate lab setup."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":117,"line_start":117}],"confidence":0.98,"description":"nmap -p 443 192.168.1.1","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":217,"line_start":217}],"confidence":0.98,"description":"enum4linux -a 192.168.1.1","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":220,"line_start":220}],"confidence":0.98,"description":"nmap --script smb-vuln* 192.168.1.1","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail."}],"files_scanned":1,"total_lines":360,"audit_model":"codex","audited_at":"2026-08-04T15:46:21.118+00:00","created_at":"2026-08-05T01:35:49.755695+00:00","static_findings":[{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":73,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":77,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":83,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":91,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":100,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":104,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":111,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":115,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":124,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":132,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":145,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":154,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":169,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":183,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":202,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":206,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":221,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":229,"severity":"medium","line_start":221},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":238,"severity":"medium","line_start":229},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":242,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":248,"severity":"medium","line_start":242},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":264,"severity":"medium","line_start":248},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":276,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":301,"severity":"medium","line_start":276},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":321,"severity":"medium","line_start":301},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":325,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":333,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":337,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":345,"severity":"medium","line_start":337},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":352,"severity":"medium","line_start":345},{"id":"external_commands:SKILL.md:81:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"# Windows PowerShell","category":"external_commands","line_end":81,"severity":"high","line_start":81},{"id":"external_commands:SKILL.md:62:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt update && sudo apt install apache2","category":"external_commands","line_end":62,"severity":"high","line_start":62},{"id":"external_commands:SKILL.md:65:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl start apache2","category":"external_commands","line_end":65,"severity":"high","line_start":65},{"id":"external_commands:SKILL.md:66:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl enable apache2","category":"external_commands","line_end":66,"severity":"high","line_start":66},{"id":"external_commands:SKILL.md:69:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"echo \"<html><body><h1>Test Page</h1></body></html>\" | sudo tee /var/www/html/index.html","category":"external_commands","line_end":69,"severity":"high","line_start":69},{"id":"external_commands:SKILL.md:79:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo ufw allow 80/tcp","category":"external_commands","line_end":79,"severity":"high","line_start":79},{"id":"external_commands:SKILL.md:93:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 \\","category":"external_commands","line_end":93,"severity":"high","line_start":93},{"id":"external_commands:SKILL.md:98:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo a2enmod ssl","category":"external_commands","line_end":98,"severity":"high","line_start":98},{"id":"external_commands:SKILL.md:99:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl restart apache2","category":"external_commands","line_end":99,"severity":"high","line_start":99},{"id":"external_commands:SKILL.md:106:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo nano /etc/apache2/sites-available/default-ssl.conf","category":"external_commands","line_end":106,"severity":"high","line_start":106},{"id":"external_commands:SKILL.md:109:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo a2ensite default-ssl","category":"external_commands","line_end":109,"severity":"high","line_start":109},{"id":"external_commands:SKILL.md:110:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl reload apache2","category":"external_commands","line_end":110,"severity":"high","line_start":110},{"id":"external_commands:SKILL.md:134:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install snmpd snmp","category":"external_commands","line_end":134,"severity":"high","line_start":134},{"id":"external_commands:SKILL.md:137:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo nano /etc/snmp/snmpd.conf","category":"external_commands","line_end":137,"severity":"high","line_start":137},{"id":"external_commands:SKILL.md:144:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl restart snmpd","category":"external_commands","line_end":144,"severity":"high","line_start":144},{"id":"external_commands:SKILL.md:185:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install samba","category":"external_commands","line_end":185,"severity":"high","line_start":185},{"id":"external_commands:SKILL.md:188:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo install -d -m 0770 -o root -g sambashare /srv/samba/share","category":"external_commands","line_end":188,"severity":"high","line_start":188},{"id":"external_commands:SKILL.md:191:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo nano /etc/samba/smb.conf","category":"external_commands","line_end":191,"severity":"high","line_start":191},{"id":"external_commands:SKILL.md:201:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl restart smbd","category":"external_commands","line_end":201,"severity":"high","line_start":201},{"id":"external_commands:SKILL.md:231:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tail -f /var/log/apache2/access.log","category":"external_commands","line_end":231,"severity":"high","line_start":231},{"id":"external_commands:SKILL.md:234:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tail -f /var/log/apache2/error.log","category":"external_commands","line_end":234,"severity":"high","line_start":234},{"id":"external_commands:SKILL.md:303:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install apache2","category":"external_commands","line_end":303,"severity":"high","line_start":303},{"id":"external_commands:SKILL.md:304:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl start apache2","category":"external_commands","line_end":304,"severity":"high","line_start":304},{"id":"external_commands:SKILL.md:307:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"cat << 'EOF' | sudo tee /var/www/html/login.html","category":"external_commands","line_end":307,"severity":"high","line_start":307},{"id":"external_commands:SKILL.md:320:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo ufw allow 80/tcp","category":"external_commands","line_end":320,"severity":"high","line_start":320},{"id":"external_commands:SKILL.md:327:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install snmpd","category":"external_commands","line_end":327,"severity":"high","line_start":327},{"id":"external_commands:SKILL.md:328:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"echo \"rocommunity public\" | sudo tee -a /etc/snmp/snmpd.conf","category":"external_commands","line_end":328,"severity":"high","line_start":328},{"id":"external_commands:SKILL.md:329:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl restart snmpd","category":"external_commands","line_end":329,"severity":"high","line_start":329},{"id":"external_commands:SKILL.md:339:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install samba","category":"external_commands","line_end":339,"severity":"high","line_start":339},{"id":"external_commands:SKILL.md:341:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo install -d -m 0770 -o root -g sambashare /srv/samba/anonymous","category":"external_commands","line_end":341,"severity":"high","line_start":341},{"id":"network:SKILL.md:72:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl http://localhost","category":"network","line_end":72,"severity":"low","line_start":72},{"id":"network:SKILL.md:123:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -kv https://192.168.1.1","category":"network","line_end":123,"severity":"low","line_start":123},{"id":"network:SKILL.md:266:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -I http://target","category":"network","line_end":266,"severity":"low","line_start":266},{"id":"network:SKILL.md:269:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -kI https://target","category":"network","line_end":269,"severity":"low","line_start":269},{"id":"network:SKILL.md:117:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"nmap -p 443 192.168.1.1","category":"network","line_end":117,"severity":"medium","line_start":117},{"id":"network:SKILL.md:120:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"openssl s_client -connect 192.168.1.1:443","category":"network","line_end":120,"severity":"medium","line_start":120},{"id":"network:SKILL.md:123:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"curl -kv https://192.168.1.1","category":"network","line_end":123,"severity":"medium","line_start":123},{"id":"network:SKILL.md:156:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"snmpwalk -c public -v1 192.168.1.1","category":"network","line_end":156,"severity":"medium","line_start":156},{"id":"network:SKILL.md:159:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"snmpwalk -c public -v1 192.168.1.1 1.3.6.1.2.1.1","category":"network","line_end":159,"severity":"medium","line_start":159},{"id":"network:SKILL.md:162:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"snmpwalk -c public -v1 192.168.1.1 1.3.6.1.2.1.25.4.2.1.2","category":"network","line_end":162,"severity":"medium","line_start":162},{"id":"network:SKILL.md:165:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"snmp-check 192.168.1.1 -c public","category":"network","line_end":165,"severity":"medium","line_start":165},{"id":"network:SKILL.md:168:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt 192.168.1.1","category":"network","line_end":168,"severity":"medium","line_start":168},{"id":"network:SKILL.md:208:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"smbclient -L //192.168.1.1 -N","category":"network","line_end":208,"severity":"medium","line_start":208},{"id":"network:SKILL.md:211:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"smbclient //192.168.1.1/share -N","category":"network","line_end":211,"severity":"medium","line_start":211},{"id":"network:SKILL.md:214:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"smbmap -H 192.168.1.1","category":"network","line_end":214,"severity":"medium","line_start":214},{"id":"network:SKILL.md:217:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"enum4linux -a 192.168.1.1","category":"network","line_end":217,"severity":"medium","line_start":217},{"id":"network:SKILL.md:220:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"nmap --script smb-vuln* 192.168.1.1","category":"network","line_end":220,"severity":"medium","line_start":220},{"id":"network:SKILL.md:356:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"| Cannot connect remotely | Bind service to 0.0.0.0 instead of localhost |","category":"network","line_end":356,"severity":"medium","line_start":356},{"id":"sensitive:SKILL.md:94:certificate-key-files","file":"SKILL.md","pattern":"Certificate/key files","snippet":"-keyout /etc/ssl/private/apache-selfsigned.key \\","category":"sensitive","line_end":94,"severity":"high","line_start":94},{"id":"sensitive:SKILL.md:95:certificate-key-files","file":"SKILL.md","pattern":"Certificate/key files","snippet":"-out /etc/ssl/certs/apache-selfsigned.crt","category":"sensitive","line_end":95,"severity":"high","line_start":95},{"id":"blocker:SKILL.md:66:systemd-service-enablement","file":"SKILL.md","pattern":"Systemd service enablement","snippet":"sudo systemctl enable apache2","category":"blocker","line_end":66,"severity":"high","line_start":66},{"id":"blocker:SKILL.md:117:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"nmap -p 443 192.168.1.1","category":"blocker","line_end":117,"severity":"high","line_start":117},{"id":"blocker:SKILL.md:217:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"enum4linux -a 192.168.1.1","category":"blocker","line_end":217,"severity":"high","line_start":217},{"id":"blocker:SKILL.md:220:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"nmap --script smb-vuln* 192.168.1.1","category":"blocker","line_end":220,"severity":"high","line_start":220},{"id":"blocker:SKILL.md:282:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"| nmap | Port scanning and scripts |","category":"blocker","line_end":282,"severity":"high","line_start":282},{"id":"blocker:SKILL.md:285:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"| enum4linux | SMB/NetBIOS enumeration |","category":"blocker","line_end":285,"severity":"high","line_start":285},{"id":"obfuscation:multiple:1:heuristic-suspicious-combination-code-execution-","file":"multiple","pattern":"[HEURISTIC] SUSPICIOUS COMBINATION: Code execution + Persistence mechanism","snippet":"This combination is common in malware that maintains access","category":"obfuscation","line_end":1,"severity":"high","line_start":1}],"finding_verdicts":[{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter, not Ruby backtick syntax or an execution API. The delimiter cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:powershell-invocation","reason":"The matched line is a Markdown comment labeling the following example as Windows PowerShell. It does not invoke a PowerShell process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:sudo-privilege-escalation","reason":"This command installs or updates system packages with root privileges on line 62. It changes the host and requires explicit operator approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:65:sudo-privilege-escalation","reason":"This root command changes a system service on line 65, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:66:sudo-privilege-escalation","reason":"This root command changes a system service on line 66, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:69:sudo-privilege-escalation","reason":"This command writes content into a root-owned system or service path on line 69. It makes a privileged host change that requires explicit approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:79:sudo-privilege-escalation","reason":"This root command changes the host firewall on line 79 and exposes an inbound service. An incorrect target or environment could expand network access.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:93:sudo-privilege-escalation","reason":"This root command creates a private key and certificate in system directories on line 93. It writes security-sensitive host configuration and needs operator approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:98:sudo-privilege-escalation","reason":"This command writes content into a root-owned system or service path on line 98. It makes a privileged host change that requires explicit approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:99:sudo-privilege-escalation","reason":"This root command changes a system service on line 99, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:106:sudo-privilege-escalation","reason":"This command opens a root-owned service configuration file for modification on line 106. Incorrect edits can weaken or disrupt the host service.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:109:sudo-privilege-escalation","reason":"This command writes content into a root-owned system or service path on line 109. It makes a privileged host change that requires explicit approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:110:sudo-privilege-escalation","reason":"This root command changes a system service on line 110, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:134:sudo-privilege-escalation","reason":"This command installs or updates system packages with root privileges on line 134. It changes the host and requires explicit operator approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:137:sudo-privilege-escalation","reason":"This command opens a root-owned service configuration file for modification on line 137. Incorrect edits can weaken or disrupt the host service.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:144:sudo-privilege-escalation","reason":"This root command changes a system service on line 144, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:185:sudo-privilege-escalation","reason":"This command installs or updates system packages with root privileges on line 185. It changes the host and requires explicit operator approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:188:sudo-privilege-escalation","reason":"This root command creates a service directory and assigns permissions on line 188. It changes filesystem ownership and access controls on the host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:191:sudo-privilege-escalation","reason":"This command opens a root-owned service configuration file for modification on line 191. Incorrect edits can weaken or disrupt the host service.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:201:sudo-privilege-escalation","reason":"This root command changes a system service on line 201, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:231:sudo-privilege-escalation","reason":"This command reads service logs with root privileges on line 231. Logs can contain sensitive request data and should only be accessed on authorized systems.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:234:sudo-privilege-escalation","reason":"This command reads service logs with root privileges on line 234. Logs can contain sensitive request data and should only be accessed on authorized systems.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:303:sudo-privilege-escalation","reason":"This command installs or updates system packages with root privileges on line 303. It changes the host and requires explicit operator approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:304:sudo-privilege-escalation","reason":"This root command changes a system service on line 304, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:307:sudo-privilege-escalation","reason":"This command writes content into a root-owned system or service path on line 307. It makes a privileged host change that requires explicit approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:320:sudo-privilege-escalation","reason":"This root command changes the host firewall on line 320 and exposes an inbound service. An incorrect target or environment could expand network access.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:327:sudo-privilege-escalation","reason":"This command installs or updates system packages with root privileges on line 327. It changes the host and requires explicit operator approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:328:sudo-privilege-escalation","reason":"This command writes content into a root-owned system or service path on line 328. It makes a privileged host change that requires explicit approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:329:sudo-privilege-escalation","reason":"This root command changes a system service on line 329, affecting availability or startup behavior. Running it outside an isolated lab could alter a real host.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:339:sudo-privilege-escalation","reason":"This command installs or updates system packages with root privileges on line 339. It changes the host and requires explicit operator approval.","verdict":"confirmed","confidence":0.97},{"id":"external_commands:SKILL.md:341:sudo-privilege-escalation","reason":"This root command creates a service directory and assigns permissions on line 341. It changes filesystem ownership and access controls on the host.","verdict":"confirmed","confidence":0.97},{"id":"network:SKILL.md:72:hardcoded-url","reason":"The URL targets localhost for local service verification and does not contact an external host. It is an explicit lab example.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:123:hardcoded-url","reason":"The URL uses a private example address or the literal placeholder target in an authorized lab command. It is not a fixed external destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:266:hardcoded-url","reason":"The URL uses a private example address or the literal placeholder target in an authorized lab command. It is not a fixed external destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:269:hardcoded-url","reason":"The URL uses a private example address or the literal placeholder target in an authorized lab command. It is not a fixed external destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:117:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:120:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:123:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:156:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:159:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:162:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:165:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:168:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:208:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:211:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:214:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:217:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:220:hardcoded-ip-address","reason":"The address 192.168.1.1 is a private RFC 1918 example target used consistently in lab documentation. It is not an embedded external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:356:hardcoded-ip-address","reason":"The troubleshooting advice recommends binding a service to 0.0.0.0. This exposes it on every interface and can unintentionally make a weak lab service reachable.","verdict":"confirmed","confidence":0.96},{"id":"sensitive:SKILL.md:94:certificate-key-files","reason":"The lines name standard output paths for a newly generated self-signed key and certificate. They do not expose or read existing key material.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:95:certificate-key-files","reason":"The lines name standard output paths for a newly generated self-signed key and certificate. They do not expose or read existing key material.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:66:systemd-service-enablement","reason":"The command enables Apache to start automatically at boot. This is a persistent system change, even though the stated purpose is legitimate lab setup.","verdict":"confirmed","confidence":0.98},{"id":"blocker:SKILL.md:117:network-scanning-tools","reason":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail.","verdict":"confirmed","confidence":0.98},{"id":"blocker:SKILL.md:217:network-scanning-tools","reason":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail.","verdict":"confirmed","confidence":0.98},{"id":"blocker:SKILL.md:220:network-scanning-tools","reason":"This is an executable enumeration or vulnerability-scanning command against a network target. It can probe systems beyond the lab if authorization and scope checks fail.","verdict":"confirmed","confidence":0.98},{"id":"blocker:SKILL.md:282:network-scanning-tools","reason":"The line only names a tool and describes its purpose in a reference table. It neither invokes the tool nor selects a target.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:285:network-scanning-tools","reason":"The line only names a tool and describes its purpose in a reference table. It neither invokes the tool nor selects a target.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:multiple:1:heuristic-suspicious-combination-code-execution-","reason":"No obfuscation or covert execution exists in the skill. The heuristic combines Markdown command examples with legitimate Apache service enablement.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Insecure SNMP Lab Configuration","severity":"high","locations":[{"file":"SKILL.md","line_end":144,"line_start":139},{"file":"SKILL.md","line_end":168,"line_start":156},{"file":"SKILL.md","line_end":332,"line_start":327}],"confidence":0.98,"description":"The guide recommends SNMP v1 with public and private community strings, then demonstrates process enumeration and community-string guessing. Exposure outside an isolated lab could disclose system details.","confidence_reasoning":"The commands and configuration explicitly use cleartext SNMP v1 and the well-known public community. The skill also acknowledges this protocol limitation."},{"title":"Anonymous Writable SMB Configuration","severity":"high","locations":[{"file":"SKILL.md","line_end":201,"line_start":193}],"confidence":0.91,"description":"The sample share enables guest access and disables read-only mode. A reachable lab host could accept unauthorized file changes if the filesystem permissions also permit them.","confidence_reasoning":"The Samba configuration explicitly sets guest access to yes and read-only to no. Actual write access still depends on the shown directory permissions and Samba identity mapping."},{"title":"Credential Collection Page Without Handling Guidance","severity":"medium","locations":[{"file":"SKILL.md","line_end":317,"line_start":307}],"confidence":0.9,"description":"The HTTP example creates a login form that requests a username and password. It omits guidance on test credentials, storage, transport, and cleanup.","confidence_reasoning":"The example visibly requests password input and posts it to login.php. No backend or exfiltration is shown, but unsafe lab handling could expose entered credentials."}],"subject_marketplace_commit_sha":"81e05e636292629114b76cbb3922fbe57672fc02","subject_content_hash":"64e8a0f23fad3c68c9b5f27115ed725dd61bbbcd281bfd3cdde4b590d853547d","subject_tree_hash":"4139395cdade48472604f76a5fdb40ea823296abf449f41c8cbafee62f925012","subject_plugin_path":"skills/sickn33/network-101","audit_payload_hash":"4b5ede5919c411d5d8ba7f3aede5bae5","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"81e05e636292629114b76cbb3922fbe57672fc02","contentHash":"64e8a0f23fad3c68c9b5f27115ed725dd61bbbcd281bfd3cdde4b590d853547d","treeHash":"4139395cdade48472604f76a5fdb40ea823296abf449f41c8cbafee62f925012","pluginPath":"skills/sickn33/network-101","auditPayloadHash":"4b5ede5919c411d5d8ba7f3aede5bae5"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-network-101/audits/6/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":7,"capabilityReviewCount":30,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}