Versioned security assessment

Report ID: SA-4CD01779

6/28/2026, 5:44:52 AM

network-netcat security assessment v6

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
network-netcat
Version
v6
Maintainer
AgentSecOps
Coverage
5 Files scanned · 2,086 Lines analyzed
Policy version
Unavailable

Highest confirmed finding severity

Medium

1 confirmed security finding requires attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Static analysis reported extensive command execution, network, and filesystem patterns. Manual review confirms critical risk in SKILL.md because it provides actionable reverse shell, bind shell, persistence, payload delivery, pivoting, and data exfiltration workflows; several findings in template reference files are benign educational examples. No evidence found of prompt injection text in the reviewed files.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

5 Files scanned · 2,086 Lines analyzed

7 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 6 evidence locations

Filesystem access

May read or write local files.

Observed in 5 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 6 evidence locations

Capability review items (6)
Critical
Actionable Reverse and Bind Shell Guidance
TRUE POSITIVE: SKILL.md gives step-by-step reverse shell, bind shell, PTY upgrade, and reconnection patterns. This enables unauthorized interactive command execution if copied outside an approved lab. Confidence 0.96. Confidence reasoning: The static shell execution findings are confirmed by multiple semantically aligned shell access sections, including Linux, Windows, PowerShell, and persistence-like reconnection examples.
The static shell execution findings are confirmed by multiple semantically aligned shell access sections, including Linux, Windows, PowerShell, and reconnection examples.
Critical
Persistent Backdoor Setup Instructions
TRUE POSITIVE: SKILL.md describes creating a persistent netcat service, cron startup entry, and Windows scheduled task. These are durable access mechanisms and match malicious persistence behavior. Confidence 0.98. Confidence reasoning: The cited section explicitly labels the pattern as a persistent backdoor and provides platform-specific persistence mechanisms.
The cited section explicitly labels the pattern as a persistent backdoor and provides platform-specific persistence mechanisms.
Critical
Data Exfiltration Workflow
TRUE POSITIVE: SKILL.md includes a data exfiltration pattern for sensitive system files, database dumps, and compressed directories over netcat. This is direct unauthorized data transfer guidance. Confidence 0.97. Confidence reasoning: The section title and examples align with exfiltration behavior, including sensitive file and database movement to an attacker-controlled listener.
The section title and examples align with exfiltration behavior, including sensitive file and database movement to an attacker-controlled listener.
High
Post-Exploitation Payload Delivery and Metasploit Use
TRUE POSITIVE: SKILL.md explains staged payload delivery and using netcat through Metasploit sessions. This materially supports post-exploitation control of compromised systems. Confidence 0.93. Confidence reasoning: The source names compromised hosts, payload stages, and Metasploit session actions, which confirms offensive post-exploitation context.
The source names compromised hosts, payload stages, and Metasploit session actions, which confirms offensive post-exploitation context.
High
Relay, Pivot, and Covert Communication Guidance
TRUE POSITIVE: SKILL.md covers relays through compromised hosts, internal network pivoting, and simple covert communication channels. These techniques can bypass segmentation and monitoring controls. Confidence 0.91. Confidence reasoning: The guidance explicitly describes relay and pivot use through compromised infrastructure, not only benign connectivity testing.
The guidance explicitly describes relay and pivot use through compromised infrastructure, not only benign connectivity testing.
Medium
Plain Netcat File Transfer Patterns
TRUE POSITIVE: SKILL.md documents file and archive transfer over netcat, including checksum verification and SSL variants. File transfer is legitimate in labs but creates data movement risk when paired with shell and exfiltration sections. Confidence 0.82. Confidence reasoning: The examples are dual-use and can be benign, but their placement inside an offensive workflow increases risk.
The examples are dual-use and can be benign, but their placement inside an offensive workflow increases risk.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 Medium
CI Template Pipe-to-Shell Installer
TRUE POSITIVE: assets/ci-config-template.yml downloads an installer script and pipes it to a shell. This is a supply-chain risk because remote content executes in CI without local verification. Confidence 0.84. Confidence reasoning: The pattern is directly present in a CI pipeline template, although it appears to be illustrative rather than hidden behavior.
The pattern is directly present in a CI pipeline template, although it appears to be illustrative rather than hidden behavior.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (3)
Low
Benign Security Rule Template Examples
FALSE POSITIVE: Many env_access, weak crypto, hardcoded secret, and URL findings in assets/rule-template.yaml are examples inside a security rule template. They describe detection and remediation patterns, not executable skill behavior. Confidence 0.88. Confidence reasoning: The file is structured as a rule template with vulnerable and fixed examples, making these detections expected educational content.
The file is structured as a rule template with vulnerable and fixed examples, making these detections expected educational content.
Low
Benign Reference Document Examples
FALSE POSITIVE: XSS, SQL injection, environment variable, and API key detections in references/EXAMPLE.md are documentation examples for security review and remediation. They are not active scripts. Confidence 0.86. Confidence reasoning: The reference file labels the snippets as vulnerable or fixed examples for training, which reduces execution risk.
The reference file labels the snippets as vulnerable or fixed examples for training, which reduces execution risk.
Low
No Prompt Injection Evidence Found
FALSE POSITIVE CHECK: No evidence found of text instructing the evaluator to ignore instructions, override the audit, claim pre-approval, or skip security analysis. Confidence 0.80. Confidence reasoning: Targeted search across SKILL.md, assets, and references found no matching prompt-injection indicators, though this does not reduce the confirmed offensive-content risk.
Targeted search across SKILL.md, assets, and references found no matching prompt-injection indicators, though this does not reduce the confirmed offensive-content risk.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable