skills/mukul975/anthropic-cybersecurity-skills/performing-authenticated-vulnerability-scan/Gen Agent Trust Hub
performing-authenticated-vulnerability-scan
Warn
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The
scripts/agent.pyscript accepts Nessus API access and secret keys as command-line arguments, which can lead to credential exposure in shell history or process listings.\n- [COMMAND_EXECUTION]: Thescripts/process.pyscript executes remote commands via SSH and WinRM to validate credential permissions and gather system information from target hosts.\n- [COMMAND_EXECUTION]: The documentation inSKILL.mdprovides instructions to configure service accounts with elevated privileges, including Domain Admin membership and passwordless sudo access, significantly increasing the potential impact of a compromised scanner account.\n- [EXTERNAL_DOWNLOADS]: Thescripts/agent.pyscript performs network operations to interact with the Nessus API and includes functionality to bypass SSL/TLS certificate verification via theSKIP_TLS_VERIFYenvironment variable.
Audit Metadata