bloodyad
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing complex shell commands via
bloodyAD,badS4U2self, andproxychains. These tools are designed for Active Directory exploitation, including resetting passwords, modifying group membership, and hijacking DNS records. - [PRIVILEGE_ESCALATION]: Recommends the use of
sudo date -u -s "<DC_time>"to modify the system clock. This command requires administrative (root) privileges on the host system. - [DATA_EXFILTRATION]: Explicitly provides commands to read sensitive Active Directory attributes, such as LAPS passwords (
ms-Mcs-AdmPwd), which involves accessing administrative credentials from a network service. - [INDIRECT_PROMPT_INJECTION]: The skill enables an attack surface where external inputs are interpolated into powerful shell commands.
- Ingestion points: Active Directory identifiers (usernames, domain names) and credentials provided during tool invocation in SKILL.md.
- Boundary markers: The instructions lack delimiters or explicit instructions for the agent to ignore potentially malicious content within processed data.
- Capability inventory: Shell execution capabilities for
bloodyADand related tools across several offensive workflows. - Sanitization: There is no evidence of input validation or escaping for the data passed to the command-line arguments.
- [CREDENTIALS_UNSAFE]: The documentation provides examples and workflows for using NTLM hashes and Kerberos ticket paths. The skill facilitates the handling and injection of sensitive authentication material into network protocols.
Recommendations
- AI detected serious security threats
Audit Metadata