skills/aeondave/malskill/bloodyad/Gen Agent Trust Hub

bloodyad

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for executing complex shell commands via bloodyAD, badS4U2self, and proxychains. These tools are designed for Active Directory exploitation, including resetting passwords, modifying group membership, and hijacking DNS records.
  • [PRIVILEGE_ESCALATION]: Recommends the use of sudo date -u -s "<DC_time>" to modify the system clock. This command requires administrative (root) privileges on the host system.
  • [DATA_EXFILTRATION]: Explicitly provides commands to read sensitive Active Directory attributes, such as LAPS passwords (ms-Mcs-AdmPwd), which involves accessing administrative credentials from a network service.
  • [INDIRECT_PROMPT_INJECTION]: The skill enables an attack surface where external inputs are interpolated into powerful shell commands.
  • Ingestion points: Active Directory identifiers (usernames, domain names) and credentials provided during tool invocation in SKILL.md.
  • Boundary markers: The instructions lack delimiters or explicit instructions for the agent to ignore potentially malicious content within processed data.
  • Capability inventory: Shell execution capabilities for bloodyAD and related tools across several offensive workflows.
  • Sanitization: There is no evidence of input validation or escaping for the data passed to the command-line arguments.
  • [CREDENTIALS_UNSAFE]: The documentation provides examples and workflows for using NTLM hashes and Kerberos ticket paths. The skill facilitates the handling and injection of sensitive authentication material into network protocols.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:41 PM
Security Audit — agent-trust-hub — bloodyad