Most critical static alerts are false positives caused by defensive examples, public references, and Markdown syntax. Actionable scanning, sensitive-data inspection, destructive removal, and an unaudited hidden-path script remain confirmed risks. The broad post-exploitation workflow creates additional high dual-use risk despite its authorization reminder.
The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets.
The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets.
The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets.
The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets.
The Web testing workflow explicitly progresses through exploitation, privilege escalation, and lateral movement, while also recommending parameter and dictionary brute forcing.
The offensive progression and brute-force guidance are explicit in the workflow. A general authorization reminder exists, but no per-action approval or technical scope control is defined.
Capability review items (28)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The guide instructs execution of a Python script from a hidden home-directory path, but that script is absent from the audited package. This can execute unverified code outside the package boundary.
This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.
This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.
This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.
- **Nikto**:`nikto -h <target> -ssl -Format html -o report.html`
This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.
The command starts OpenVAS and passes a scanner password on the command line. It changes service state and can expose the supplied password through shell history or process inspection.
This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.
This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data.
This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data.
This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data.
The skill supplies an actionable recursive ClamAV command with --remove. Executing it can delete files without quarantine, review, or per-file confirmation.
The regeneration command accesses and executes a script under ~/.hermes rather than a package-relative audited file. The external hidden path creates an integrity and provenance risk.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
- **Osquery**:`osqueryi "SELECT * FROM processes WHERE name LIKE '%malware%';"`
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.
Most detections are false positives caused by Markdown code spans, defensive payload examples, and links to recognized security references. Confirmed risks include an unaudited home-directory script and active Nmap commands; semantic review also found destructive deletion, process-argument credential exposure, and a broad offensive workflow. Authorization guidance is present, but high-impact actions still need enforceable scope and confirmation controls.
The Nmap command performs active service, script, and operating-system probes against a target. The authorization guidance reduces misuse intent, but an incorrect scope can still disrupt or scan third-party systems.
This ready-to-run Nmap command enables aggressive detection, scripts, and operating-system fingerprinting. It can create substantial target traffic and expose services if executed outside the authorized scope.
The command scans every TCP port at a minimum rate of 1,000 packets per second. This is an intrusive operation that can affect production systems or trigger defensive controls.
This command actively probes selected ports for service versions. It is legitimate within written scope, but remains a real network action with operational and authorization risk.
The workflow directs agents through exploitation, privilege escalation, lateral movement, and password attacks. Prose authorization checks do not enforce targets or phase-specific approval.
The offensive stages and Burp Intruder password attack guidance are explicit. Authorization is required elsewhere, but no enforceable scope control is defined.
The ClamAV example uses --remove during recursive scanning. False positives or an incorrect path could delete important files without quarantine or recovery.
The documented command explicitly combines recursive scanning with automatic removal. The line provides no confirmation, quarantine, backup, or recovery step.
The OpenVAS example supplies a password through a command-line flag. Real credentials can remain visible in process listings, terminal logs, or shell history.
The --gmp-password flag is explicit, although the value is a placeholder. Replacing it with a real secret creates a well-known local exposure path.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The guide instructs Python to execute a generator under ~/.hermes, but the audited file tree contains no such script. A planted or stale file at that unaudited path could run with the agent's privileges.
This accesses a hidden home-directory path outside the audited files and immediately passes it to Python. The package provides no file whose contents can be verified at that path.
Most detections are false positives caused by Markdown code spans, defensive payload examples, and links to recognized security references. Confirmed risks include an unaudited home-directory script and active Nmap commands; semantic review also found destructive deletion, process-argument credential exposure, and a broad offensive workflow. Authorization guidance is present, but high-impact actions still need enforceable scope and confirmation controls.
The Nmap command performs active service, script, and operating-system probes against a target. The authorization guidance reduces misuse intent, but an incorrect scope can still disrupt or scan third-party systems.
This ready-to-run Nmap command enables aggressive detection, scripts, and operating-system fingerprinting. It can create substantial target traffic and expose services if executed outside the authorized scope.
The command scans every TCP port at a minimum rate of 1,000 packets per second. This is an intrusive operation that can affect production systems or trigger defensive controls.
This command actively probes selected ports for service versions. It is legitimate within written scope, but remains a real network action with operational and authorization risk.
The workflow directs agents through exploitation, privilege escalation, lateral movement, and password attacks. Prose authorization checks do not enforce targets or phase-specific approval.
The offensive stages and Burp Intruder password attack guidance are explicit. Authorization is required elsewhere, but no enforceable scope control is defined.
The ClamAV example uses --remove during recursive scanning. False positives or an incorrect path could delete important files without quarantine or recovery.
The documented command explicitly combines recursive scanning with automatic removal. The line provides no confirmation, quarantine, backup, or recovery step.
The OpenVAS example supplies a password through a command-line flag. Real credentials can remain visible in process listings, terminal logs, or shell history.
The --gmp-password flag is explicit, although the value is a placeholder. Replacing it with a real secret creates a well-known local exposure path.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The guide instructs Python to execute a generator under ~/.hermes, but the audited file tree contains no such script. A planted or stale file at that unaudited path could run with the agent's privileges.
This accesses a hidden home-directory path outside the audited files and immediately passes it to Python. The package provides no file whose contents can be verified at that path.
Most detections are false positives caused by Markdown code spans, defensive payload examples, and links to recognized security references. Confirmed risks include an unaudited home-directory script and active Nmap commands; semantic review also found destructive deletion, process-argument credential exposure, and a broad offensive workflow. Authorization guidance is present, but high-impact actions still need enforceable scope and confirmation controls.
The Nmap command performs active service, script, and operating-system probes against a target. The authorization guidance reduces misuse intent, but an incorrect scope can still disrupt or scan third-party systems.
This ready-to-run Nmap command enables aggressive detection, scripts, and operating-system fingerprinting. It can create substantial target traffic and expose services if executed outside the authorized scope.
The command scans every TCP port at a minimum rate of 1,000 packets per second. This is an intrusive operation that can affect production systems or trigger defensive controls.
This command actively probes selected ports for service versions. It is legitimate within written scope, but remains a real network action with operational and authorization risk.
The workflow directs agents through exploitation, privilege escalation, lateral movement, and password attacks. Prose authorization checks do not enforce targets or phase-specific approval.
The offensive stages and Burp Intruder password attack guidance are explicit. Authorization is required elsewhere, but no enforceable scope control is defined.
The ClamAV example uses --remove during recursive scanning. False positives or an incorrect path could delete important files without quarantine or recovery.
The documented command explicitly combines recursive scanning with automatic removal. The line provides no confirmation, quarantine, backup, or recovery step.
The OpenVAS example supplies a password through a command-line flag. Real credentials can remain visible in process listings, terminal logs, or shell history.
The --gmp-password flag is explicit, although the value is a placeholder. Replacing it with a real secret creates a well-known local exposure path.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The guide instructs Python to execute a generator under ~/.hermes, but the audited file tree contains no such script. A planted or stale file at that unaudited path could run with the agent's privileges.
This accesses a hidden home-directory path outside the audited files and immediately passes it to Python. The package provides no file whose contents can be verified at that path.