skills/aeondave/malskill/bloodhound/Gen Agent Trust Hub

bloodhound

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSOBFUSCATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the user to download and immediately execute remote configuration files using docker-compose: `curl -L https://ghst.ly/getbhce | docker compose -f
  • up -dinSKILL.md.\n- **[EXTERNAL_DOWNLOADS]:** The skill fetches resources from external domains not included in the trusted vendor list, including ghst.lyandraw.githubusercontent.com.\n- **[OBFUSCATION]:** The skill utilizes a URL shortener (ghst.ly`) to point to the BloodHound setup script, which masks the final destination and source content from simple string-based scanners.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that ingests large amounts of untrusted data from Active Directory environments for analysis, creating a surface for indirect prompt injection.\n
  • Ingestion points: Active Directory metadata and objects collected via SharpHound and bloodhound-python in SKILL.md.\n
  • Boundary markers: None present in the instructional workflow.\n
  • Capability inventory: Shell command execution (SharpHound, docker), file system operations, and network API calls.\n
  • Sanitization: No sanitization or validation of the ingested data is specified in the provided reference.\n- [COMMAND_EXECUTION]: The skill contains instructions for executing binary executables (SharpHound.exe), Python scripts (bloodhound-python, certihound), and system commands (docker, curl, jq).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — bloodhound