Skip to content
ATR-2026-00156highPrivilege Escalationdraft

SSH Remote Command Execution with Credential Exposure

Detects skills that provide SSH command templates with hardcoded credential paths and remote execution patterns. This skill exposes SSH private key paths in environment variables and provides ready-to-execute remote command templates that could be weaponized for lateral movement or unauthorized access to production servers.

Severity
high
Category
Privilege Escalation
Scan Target
mcp
Author
Threat Cloud LLM Analyzer

Response Actions

alertsnapshot