Skip to content

Hide Navigation Hide TOC

SSH Remote Command Execution with Credential Exposure - ATR-2026-00156 (cf2af7f5-7609-5fc8-a152-32807c916eda)

Detects skills that provide SSH command templates with hardcoded credential paths and remote execution patterns. This skill exposes SSH private key paths in environment variables and provides ready-to-execute remote command templates that could be weaponized for lateral movement or unauthorized access to production servers.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern SSH Remote Command Execution with Credential Exposure - ATR-2026-00156 (cf2af7f5-7609-5fc8-a152-32807c916eda) Agent Threat Rules 1