poshc2
Fail
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and execute a script from a remote URL (https://raw.githubusercontent.com/nettitude/PoshC2/master/Install.sh) by piping it directly to the bash shell. This allows the execution of arbitrary remote code during the installation process.- [COMMAND_EXECUTION]: The skill contains several commands that allow for arbitrary and dangerous system operations.
- Evidence: The
run <cmd>andinject-shellcodecommands facilitate the execution of arbitrary code and process manipulation. - Evidence: The
get-systemcommand is designed to perform automated privilege escalation on the host system.- [CREDENTIALS_UNSAFE]: The skill incorporates tools specifically designed for harvesting sensitive credentials. - Evidence: The
invoke-mimikatzcommand is used to extract clear-text passwords and other secrets from system memory.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/nettitude/PoshC2/master/Install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata