bloodhound
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSOBFUSCATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to download and immediately execute remote configuration files using docker-compose: `curl -L https://ghst.ly/getbhce | docker compose -f
- up -d
inSKILL.md.\n- **[EXTERNAL_DOWNLOADS]:** The skill fetches resources from external domains not included in the trusted vendor list, includingghst.lyandraw.githubusercontent.com.\n- **[OBFUSCATION]:** The skill utilizes a URL shortener (ghst.ly`) to point to the BloodHound setup script, which masks the final destination and source content from simple string-based scanners.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that ingests large amounts of untrusted data from Active Directory environments for analysis, creating a surface for indirect prompt injection.\n - Ingestion points: Active Directory metadata and objects collected via
SharpHoundandbloodhound-pythoninSKILL.md.\n - Boundary markers: None present in the instructional workflow.\n
- Capability inventory: Shell command execution (
SharpHound,docker), file system operations, and network API calls.\n - Sanitization: No sanitization or validation of the ingested data is specified in the provided reference.\n- [COMMAND_EXECUTION]: The skill contains instructions for executing binary executables (
SharpHound.exe), Python scripts (bloodhound-python,certihound), and system commands (docker,curl,jq).
Audit Metadata