ad-discovery
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of numerous external security tools and scripts including NetExec, Impacket, BloodHound, certipy, and bloodyAD. This behavior is consistent with the skill's primary purpose of performing AD reconnaissance.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests and processes untrusted data from the Active Directory environment (e.g., user descriptions, filenames, GPP XML files) without explicit sanitization or boundary markers.
- Ingestion points: SKILL.md (via tools such as nxc, manspider, and certipy find)
- Boundary markers: Absent for processed data content
- Capability inventory: Subprocess calls to tools like nxc, bloodhound-python, and python3 scripts
- Sanitization: No sanitization or validation of retrieved AD data is described
Audit Metadata