skills/aeondave/malskill/crackmapexec/Gen Agent Trust Hub

crackmapexec

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides several command-line examples for executing nxc (NetExec) and manspider to interact with network services and extract system secrets.
  • Evidence: Includes commands for SMB authentication checks, RID cycling, share spidering, and dumping SAM/LSA/NTDS secrets from target hosts.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents modules designed to ingest and process data from external, untrusted sources (SMB shares), which creates a vulnerability surface where malicious content on those shares could influence the agent's behavior.
  • Ingestion points: Remote network shares crawled by the spider_plus module and document contents parsed by the manspider tool.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are provided in the documented command workflows.
  • Capability inventory: The skill commands have the capability to perform network scanning, credential validation, and secret extraction (--sam, --lsa, --ntds).
  • Sanitization: No evidence of content sanitization or validation is present in the skill's instructions for handling results from the spidering process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — crackmapexec