skills/aeondave/malskill/impacket/Gen Agent Trust Hub

impacket

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous CLI examples for executing Impacket scripts (e.g., secretsdump.py, psexec.py, ntlmrelayx.py). These commands are intended for use by a security professional during authorized testing.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a significant attack surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to run tools that interact with remote Active Directory environments and parse their outputs (e.g., secretsdump.py output parsing, findDelegation.py interpretation).
  • Boundary markers: None are present in the provided instructions to help the agent distinguish between tool metadata and potentially malicious instructions embedded in AD object names or properties.
  • Capability inventory: The skill encourages the use of psexec.py and wmiexec.py for shell access, ntlmrelayx.py for command execution, and secretsdump.py for credential harvesting.
  • Sanitization: There are no instructions for the agent to sanitize or validate the content returned from these network-facing tools before processing it.
  • [SAFE]: The installation instructions point to the official GitHub repository for Impacket (github.com/fortra/impacket), which is a well-known and trusted source in the security community. The skill author, AeonDave, provides legitimate documentation for these tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — impacket