privilege-escalation-knowledge
Linux の権限昇格経路を監査する
Linux の権限昇格レビューには、慎重な列挙と厳格な承認が必要です。このスキルは、管理されたラボおよび防御的監査向けに、一般的なチェック、リスクの高いベクトル、証拠取得を整理します。
この Skill を自動インストールしないでください。
基準ポリシーにより、インストール操作の前にオペレーターのレビューが必要です。
自分のエージェントでインストール
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "privilege-escalation-knowledge" from https://skillstore.io/skills/charleskozel-privilege-escalation-knowledge.md and its manifest at https://skillstore.io/api/skills/charleskozel-privilege-escalation-knowledge/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
エージェントが読めるリソース
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
テストする
「privilege-escalation-knowledge」を使用しています。 このスキルをセキュリティリード向けに要約してください。
期待される結果:
このスキルは、承認済みラボ向けに Linux 権限昇格チェックを整理します。一般的な弱点、機密性の高い証拠、レポート作成の要件を対象とします。
「privilege-escalation-knowledge」を使用しています。 このスキルから防御的チェックリストを作成してください。
期待される結果:
- 不要な昇格コマンドがないか sudo ルールを確認する。
- 想定外の SUID バイナリとリスクの高い capabilities を削除する。
- 機密ファイル、履歴、キー、サービス定義へのアクセスを制限する。
「privilege-escalation-knowledge」を使用しています。 エクスプロイトコマンドなしでラボ報告を作成してください。
期待される結果:
報告には、失敗した制御、ビジネス影響、証拠ソース、修復担当者を記載する必要があります。実行可能なエクスプロイト手順は省略する必要があります。
セキュリティ監査
重大The skill is an explicit Linux privilege escalation playbook that instructs enumeration, exploitation, root persistence, and flag capture. Confirmed findings include sudo abuse, SUID abuse, capabilities, Docker socket access, credential discovery, and sensitive file modification. Several Markdown fence and read-only enumeration detections are false positives for their exact pattern.
確認済みのセキュリティ上の懸念 (38)
確認済みの38件をすべて表示
機能レビュー項目 (126)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
🌐 ネットワークアクセス (5)
📁 ファイルシステムへのアクセス (33)
検出されたパターン
このレポートを共有・引用
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
レポートリンクをコピー
https://skillstore.io/skills/charleskozel-privilege-escalation-knowledge/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdownバッジ
[](https://skillstore.io/skills/charleskozel-privilege-escalation-knowledge?utm_source=security_passport_badge)HTMLバッジ
<a href="https://skillstore.io/skills/charleskozel-privilege-escalation-knowledge?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/charleskozel-privilege-escalation-knowledge/security.svg" alt="Skillstore security assessment" loading="lazy"></a>埋め込みカード
<iframe src="https://skillstore.io/embed/skills/charleskozel-privilege-escalation-knowledge.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>学術引用 (APA · BibTeX · CFF)
APA形式の引用
CharlesKozel. (2026). privilege-escalation-knowledge security audit report (audit version 10) [Author version unspecified]. Skillstore. https://skillstore.io/skills/charleskozel-privilege-escalation-knowledge/audits/10BibTeX形式の引用
@techreport{charleskozel-charleskozel-privilege-escalation-knowledge-2026,
author = {CharlesKozel},
title = {privilege-escalation-knowledge security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/charleskozel-privilege-escalation-knowledge/audits/10},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "privilege-escalation-knowledge security audit report (audit version 10)"
version: "unspecified"
type: report
authors:
- name: "CharlesKozel"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/charleskozel-privilege-escalation-knowledge/audits/10"
identifiers:
- type: other
value: "skillstore:charleskozel-privilege-escalation-knowledge:audit:10"
description: "Skillstore immutable audit report identifier"
Skillstore スコア
このスコアの理由 証拠の信頼度: 中作成できるもの
ラボチェックリストを準備する
セキュリティ研修生は、承認済みの CTF またはラボでの権限昇格作業を体系化できます。
ハードニングのギャップを確認する
システム所有者は、調査結果を一般的な設定ミスと比較し、修正の優先順位を付けることができます。
Marketplace リスクを評価する
レビュアーは、このスキルに厳格な公開およびインストール制御が必要な理由を特定できます。
これらのプロンプトを試す
承認済みの Linux ラボにおいて、このスキルが対象とする権限昇格レビューの段階を要約してください。エクスプロイトコマンドは含めないでください。
このスキルのガイダンスを、sudo、SUID、capabilities、cron、services、containers、および機密ファイルに関する防御的チェックリストに変換してください。
次の承認済み監査メモを前提として: [paste notes]、各項目を想定されるリスク領域と安全な修復優先度に対応付けてください。
完了済みの承認済みラボについて、運用可能なエクスプロイト詳細を含めずに、権限昇格経路、失敗した制御、修復手順を要約してください。
ベストプラクティス
- 承認とスコープが文書化されているシステムでのみ使用してください。
- 実行可能な手順よりも、防御的な要約と修復計画を優先してください。
- フラグ、認証情報、キー、ログは機密データとして扱ってください。
回避
- スコープ外のシステムで権限昇格コマンドを実行しないでください。
- 書面による承認なしにアクセスを維持したり、キーを追加したり、アカウントを変更したりしないでください。
- 一般ユーザー向けドキュメントに生のエクスプロイト手順を公開しないでください。
よくある質問
このスキルは本番システムに対して安全ですか?
このスキルは誰が使用すべきですか?
それ自体でコマンドを実行しますか?
防御担当者はこの資料を安全に使用できますか?
公開リスクが高いのはなぜですか?
広範な配布の前に何を削除すべきですか?
開発者情報
作成者
CharlesKozelライセンス
MIT
Skillstore リビジョン
r1
バージョンに関する注意
作者はバージョンを宣言していません。
リポジトリ
https://github.com/CharlesKozel/Pentest-Agent-Evalulator/tree/main/agents/claude-tbug/skills/privesc参照
3e4b6c31a74a3bd1a291c98cf585d720cb9fbc88
メンテナンスの新しさ
2026/7/26
利用状況
6 ダウンロード · 167 閲覧
ファイル構成
📄 SKILL.md