inveigh
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to execute local binaries and PowerShell modules that perform sensitive network operations.
- Evidence: Usage of
.\Inveigh.exeandInvoke-Inveighin PowerShell. - [DATA_EXFILTRATION]: The tool is designed to intercept, log, and display sensitive NTLMv1/v2 hashes and cleartext credentials from the local network.
- Evidence: Commands like
GET NTLMV2UNIQUE,GET CLEARTEXT, and the-FileOutput Yflag which writes captured data to disk. - [PRIVILEGE_ESCALATION]: The skill explicitly directs the agent to operate with high privileges, which is required for the tool's core functionality.
- Evidence: The documentation states, "Requires local admin for raw socket access."
- [INDIRECT_PROMPT_INJECTION]: The skill describes a tool that ingests untrusted network protocol data, creating a surface for indirect injection of malicious content into the agent's context.
- Ingestion points: Network broadcast and multicast traffic (LLMNR, NBT-NS, mDNS, DNS, DHCPv6) processed by the tool (SKILL.md).
- Boundary markers: Absent; the skill does not specify delimiters or warnings for the captured network data displayed in the console.
- Capability inventory: Raw socket access, file system writes (
-FileOutput Y), and interactive console output (SKILL.md). - Sanitization: No evidence of sanitization or filtering of intercepted network data before it is rendered or stored.
Audit Metadata