skills/aeondave/malskill/watson/Gen Agent Trust Hub

watson

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONPERSISTENCECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill is primarily designed to identify and facilitate local privilege escalation on Windows systems by mapping missing security patches to known exploits like PrintNightmare, ElevatedPotato, and various kernel elevation vulnerabilities.\n- [COMMAND_EXECUTION]: The instructions involve executing binary files (Watson.exe) and sensitive system commands to query service status, task lists, and installed patches (e.g., sc query, tasklist, Get-HotFix, wmic).\n- [EXTERNAL_DOWNLOADS]: The workflow documentation encourages downloading exploit source code and Proof-of-Concept (PoC) scripts from external repositories such as GitHub and Exploit-DB, which involves fetching unverified code from third-party sources.\n- [DYNAMIC_EXECUTION]: The skill provides instructions for the runtime compilation of C/C++ source code using compilers like gcc or Visual Studio to create executable exploits on the target system.\n- [PERSISTENCE]: The documentation describes methods for maintaining long-term access, specifically detailing the creation of Kerberos "Golden Tickets" following a Zerologon domain compromise.\n- [CREDENTIALS_UNSAFE]: The skill references credential harvesting techniques, including instructions on using tools like Mimikatz to dump memory from the LSASS process to extract sensitive user credentials.\n- [INDIRECT_PROMPT_INJECTION]: The skill parses output from external binaries which could potentially contain malicious instructions.\n
  • Ingestion points: Data entering agent context via Watson.exe output redirection in SKILL.md and patching-workflow.md.\n
  • Boundary markers: Absent; no delimiters or warnings are used to isolate tool output from instruction processing.\n
  • Capability inventory: Includes subprocess execution of binaries (Watson.exe), system utility execution (sc, tasklist, wmic), and runtime compilation (gcc).\n
  • Sanitization: Absent; no filtering or validation of the tool's output is described before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — watson