skills/aeondave/malskill/trevorspray/Gen Agent Trust Hub

trevorspray

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions and templates for executing the trevorspray command-line tool. These instructions facilitate automated, threaded password spraying and username enumeration against Microsoft 365, Azure AD, ADFS, and Okta endpoints. The commands include parameters for controlling threads, delays, and proxies to evade detection and lockout policies.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that ingests external data files to perform actions, which creates an attack surface for indirect prompt injection.
  • Ingestion points: The skill instructions involve reading data from external files specified by the user, such as users.txt and passwords.txt via the -u and -P flags.
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore potentially malicious content within these input files.
  • Capability inventory: The skill possesses the capability to execute shell commands and perform network-based authentication requests against remote servers.
  • Sanitization: The instructions do not define any sanitization or validation logic for the content loaded from the external files before it is passed to the tool's execution string.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — trevorspray